Fieldwerk is built by a small team, and we genuinely want to hear about security problems before anyone else does. This page sets out how to report one and the ground rules we ask you to follow.
How to report
Email security@fieldwerk.ai. Tell us what you found, where (a URL or endpoint), and the steps to reproduce it. A proof of concept helps; a video is fine. We will acknowledge your report promptly, keep you informed as we work on it, and tell you when it is fixed.
This contact is also published at /.well-known/security.txt.
Ground rules
- Test only against accounts and workspaces you own. Do not access, modify, or delete anyone else's data; if you stumble into it, stop and report what happened.
- Take only what you need to prove the issue. Do not keep, share, or use any data you encountered.
- Do not degrade the service for others: no denial-of-service testing, no spam, no high-volume automated scanning.
- No social engineering of our team or our users, and no physical attacks.
- Issues in our third-party providers (hosting, authentication, and the like) belong to their disclosure programmes, not ours.
- Give us a reasonable opportunity to fix the issue before any public disclosure, and agree timing with us.
Where we stand
We do not intend to take action against research that follows these rules. We do not run a bounty programme and do not pay for reports; what we offer is a prompt human response and a fix.