Forge Orbital

Responsible Disclosure

Vulnerability Disclosure Policy

Effective July 8, 2026 ยท Version 1.0

Forge welcomes good-faith vulnerability reports. They help protect the systems and the data behind them. This policy defines the safe path for reporting and coordinated disclosure.

Scope

Reports are welcome for publicly reachable Forge Orbital systems. No other target is in scope. Do not test any customer or third-party environment. If you believe you hold written authorization for a specific target, contact Forge first and do not test until Forge confirms it in writing.

Do not test third-party systems, customer systems, employee accounts, vendor systems, or non-public Forge environments unless written authorization covers that exact target.

Allowed Research

  • Non-destructive testing that does not degrade service.
  • Low-volume validation of a suspected vulnerability.
  • Findings involving authentication, authorization, data exposure, injection, cryptographic misuse, or configuration weaknesses.

Prohibited Activity

  • Denial-of-service, load testing, spam, phishing, social engineering, or physical attacks.
  • Exfiltration, modification, deletion, or retention of data beyond minimal proof.
  • Public disclosure before Forge has had a reasonable opportunity to investigate and remediate.

Report Contents

  • Affected URL, endpoint, version, or artifact.
  • Clear reproduction steps and observed impact.
  • A description of the minimal screenshots, logs, payloads, or request IDs that validate the issue. Do not attach large artifacts; Forge opens a channel for them during triage.
  • Your preferred name, organization, and disclosure-credit preference.

Forge Response Process

  • Acknowledgment target: one business day.
  • Initial triage target: three business days.
  • Severity model: CVSS v3.1 baseline (CVSS v4.0 accepted and normalized to v3.1 for tracking), adjusted for exploitability and customer impact.
  • Disclosure target: coordinated public disclosure after remediation, typically within 90 days for confirmed vulnerabilities.

Safe Harbor

Research conducted within this policy is authorized access to the in-scope systems named above. Forge will not bring or support a legal claim, including under the CFAA or DMCA, for good-faith research that stays within this policy, is reported within five business days of discovery, and is performed without privacy violation, data destruction, service degradation, extortion, or unauthorized persistence. If a third party brings a claim over research that followed this policy, Forge will make the authorization known.

Researchers who report valid vulnerabilities responsibly may be listed on the Forge Security Hall of Fame unless they prefer to remain anonymous. Forge does not currently operate a paid bug bounty program.