Vulnerability Disclosure Policy
Last updated September 23, 2026
We want Ferndesk to be safe for the teams and readers who rely on it. If you believe you have found a security vulnerability, please tell us. We will work with you to understand it and fix it.
1. How to report
Email [email protected]. Please include:
- what you found and where (the URL, endpoint or feature);
- the steps needed to reproduce it;
- what an attacker could do with it, as you understand it;
- your name or handle, if you would like to be credited.
Please send only the data needed to show the problem. If you came across anyone else’s information, describe it rather than attaching it.
This address is also listed in our security.txt.
2. Scope
In scope:
- the Ferndesk web application and dashboard at ferndesk.com;
- the Ferndesk API and integration endpoints at engine.ferndesk.com;
- help centers and the help widget hosted by Ferndesk, tested against a workspace you own;
- files served from static.ferndesk.com;
- the Ferndesk Chrome extension.
Out of scope:
- services run by third parties we use (please report those to the provider);
- social engineering, phishing or physical attacks against Ferndesk staff or customers;
- denial of service, load testing or anything that degrades the service for others;
- reports from automated scanners without a demonstrated, practical impact;
- missing best-practice headers, email records (SPF, DKIM, DMARC) or cookie flags, without a demonstrated impact;
- self-XSS, and clickjacking on pages with no sensitive actions.
3. Testing guidelines
- Use your own account and workspace. Create a second one if you need to test access between workspaces.
- Do not access, change or delete data that is not yours. If you reach someone else’s data by accident, stop, do not keep it, and tell us.
- Do not run tests that could affect the availability of Ferndesk for other people.
- Give us a reasonable chance to fix the issue before you tell anyone else about it (see section 6).
4. Safe harbor
If you act in good faith and follow this policy, we will:
- consider your research authorized, and not take or support legal action against you for it;
- waive the parts of our Terms of Service that would otherwise forbid it, only as far as needed for research within this policy;
- if someone else takes legal action against you for research within this policy, make it known that you acted with our authorization.
Good faith means avoiding harm to Ferndesk, our customers and their readers, and not using what you find for anything other than reporting it to us. We cannot authorize testing of systems we do not own. If you are unsure whether something is allowed, ask us at [email protected] before you do it.
5. What you can expect from us
- Acknowledgement within 3 business days of your report.
- An initial assessment, including whether we can reproduce the issue, within 10 business days.
- Updates at least every two weeks until the issue is resolved, and a message when it is fixed.
- Credit for the finding, if you would like it, once the fix is released.
We do not run a paid bug bounty program. Any reward is at our discretion.
6. Disclosure
We ask that you do not share details of a vulnerability until it has been fixed, or until 90 days have passed since your report, whichever comes first. If we need longer, we will explain why and agree a date with you. We are happy to coordinate the timing of any write-up.