Safe Harbor
Research conducted within this policy is authorized access to the in-scope systems named above.
Forge will not bring or support a legal claim, including under the CFAA or DMCA, for good-faith research
that stays within this policy, is reported within five business days of discovery, and is performed without
privacy violation, data destruction, service degradation, extortion, or unauthorized persistence. If a
third party brings a claim over research that followed this policy, Forge will make the authorization known.
Researchers who report valid vulnerabilities responsibly may be listed on the
Forge Security Hall of Fame unless they prefer to remain anonymous.
Forge does not currently operate a paid bug bounty program.