1. Reporting
Email security@frameshot.ai. Do not file a public GitHub issue for a security finding. Do not post the report on social media or a disclosure list before we have had a chance to fix it.
Include as much of the following as you have:
- What is affected (URL, product surface, account type).
- Steps to reproduce, or a proof of concept that does not destroy data.
- Impact — what an attacker could read, change, or deny.
- Your contact details if they differ from the sending address.
2. Scope
In scope: frameshot.ai and its production hosts (including app.frameshot.ai, auth.frameshot.ai, and the public marketing site), the Frameshot web application, and our production infrastructure as it is exposed to the internet.
Out of scope unless we ask otherwise:
- Denial-of-service or volume flooding.
- Social engineering of employees or customers.
- Physical attacks on people or offices.
- Findings that require a compromised employee laptop or leaked admin credentials we already treat as an incident.
- Issues that exist only on localhost, preview deploys, or a cloned project you created.
3. What we will do
We triage reports within one business day. We will tell you whether we accepted the report, need more detail, or consider it out of scope. There is no paid bug-bounty program today. We will not take legal action against a researcher who reports in good faith, stays in scope, and gives us a reasonable window to fix a real issue before publishing.
4. Other contacts
Account, billing, or product problems go to Contact, not this address. Acceptable-use and abuse reports also go to security@frameshot.ai — see the Acceptable Use Policy. Copyright notices follow the DMCA process.