generated: '2026-09-02' method: searched source: https://formboost.app/security url: https://formboost.app/security policy_published: true contact: security@formboost.app contact_type: email security_txt: published: false probed: https://formboost.app/.well-known/security.txt status: 404 note: >- No RFC 9116 security.txt. The reporting address is published on an HTML page only, so an automated scanner following the well-known convention will not find it. This is the single cheapest security improvement available to Formboost. bug_bounty: program: false platform: null note: >- No HackerOne, Bugcrowd or Intigriti program. No published reward. Searched the security page and the site; nothing found. safe_harbor: offered: true statement: >- "We will not pursue action against good-faith research that respects other people's data." scope_limitation: >- "Please do not test against forms that are not yours." A meaningful constraint here — form aliases are public by design and every one belongs to a customer, so nearly every live endpoint is out of scope for a researcher. process: submission: >- Email security@formboost.app "with enough detail to reproduce it." acknowledgement: >- "We will acknowledge your report, keep you updated while we fix it." sla: null sla_note: No acknowledgement or remediation timeframe is committed to. disclosure_policy: null disclosure_note: No coordinated-disclosure timeline is published. evidence: - source: https://formboost.app/security kind: disclosure page status: 200 verified: '2026-09-02' section: 'Reporting a vulnerability'