Security

Vulnerability Disclosure Policy

Fenko Limited’s vulnerability disclosure policy. How to report a security issue, what is in scope, response timelines, and safe harbour for good faith research.

Fenko runs security testing for other people. We expect the same scrutiny of our own systems, and we would rather hear about a problem from you than from an incident.

This policy tells you how to report a vulnerability, what we will do with it, and what protection you have when you report in good faith.

How to report

Email security@fenko.nz with:

  • The affected host, URL, or product
  • What the issue is and how to reproduce it
  • What an attacker could do with it
  • Any proof of concept, logs, or screenshots

Machine readable contact details are published at /.well-known/security.txt under RFC 9116.

Scope

In scope:

  • fenko.nz and its subdomains
  • riskyplugins.com and its subdomains
  • Fenko products and open source projects published under FenkoHQ
  • Fenko-operated infrastructure that supports the above

Out of scope:

  • Third party services we consume but do not operate. Report those to the vendor.
  • Findings from client engagements. Those are covered by the engagement agreement, not this policy.
  • Reports with no demonstrated security impact: missing headers, weak TLS ciphers with no exploit path, version banners, SPF or DMARC opinions, self-XSS, clickjacking on pages with no state changing action.
  • Social engineering of staff, suppliers, or clients.
  • Physical attacks against offices or hardware.
  • Denial of service, load testing, and resource exhaustion.
  • Automated scanner output pasted without analysis.

What we ask

  • Give us a reasonable window to fix the issue before disclosing it publicly. We suggest 90 days and will talk to you if we need longer.
  • Use only accounts and data you own. Stop as soon as you have confirmed the issue.
  • Do not access, modify, download, or delete anyone else’s data.
  • Do not degrade our service or anyone else’s.
  • Follow New Zealand law and the law where you are.

What we commit to

  • We acknowledge your report within 3 business days.
  • We give you an initial assessment, including severity and whether we accept it, within 10 business days.
  • We keep you updated while we work on a fix.
  • We tell you when the fix ships.

We do not run a paid bug bounty. If you want credit, we will name you when we publish the fix. If you would rather stay anonymous, say so.

Safe harbour

If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, and we will not report you to law enforcement over the research itself.

If a third party brings action against you for work that stayed inside this policy, tell us and we will make your compliance clear.

This protection covers your research. It does not cover using what you find to cause harm.

Encryption

We do not currently publish a PGP key. If you need an encrypted channel before sending details, email security@fenko.nz and we will arrange one.