This policy is provided for review and must be confirmed by legal counsel before public launch.
Airfree welcomes reports from security researchers who help us keep the platform safe. This policy explains how to report a vulnerability and what you can expect from us.
1. Our commitment
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, will work with you to understand and resolve the issue quickly, and will not pursue or support legal action against you related to your report.
2. Scope and guidelines
This policy covers the production Airfree Services. When testing, please observe the following.
- Only test against your own account or data, or accounts for which you have explicit permission.
- Do not access, modify, or destroy data that is not yours, and do not degrade the Services for others.
- Do not perform denial-of-service testing, social engineering, or physical attacks.
- Stop testing and report immediately if you encounter personal data, and do not retain, copy, or disclose it.
3. How to report
Report suspected vulnerabilities to our security team via /contact, or to the security contact published for the platform. Please include enough detail to reproduce the issue — affected endpoint, steps, and impact — and give us reasonable time to remediate before any public disclosure.
4. What to expect
We will acknowledge your report, keep you informed of our progress, and let you know when the issue is resolved. We are grateful for responsible disclosure and are happy to credit researchers who wish to be acknowledged.