Trust
Security is a first-class concern at Foundbrew. This page describes the controls we operate and the process for reporting a vulnerability. If you believe member data or the platform is at risk, tell us — we want to hear from you.
Last updated · 1 September 2026
01
02
Email foundbrew@gmail.com. Include a clear description, the steps to reproduce, the impact, and any proof-of-concept. Encrypt sensitive details if you can; request our PGP key in your first message.
We will acknowledge within 3 business days, keep you updated at least every 10 business days, and let you know when the issue is resolved. We do not currently run a paid bounty, but we credit reporters who want recognition.
03
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will not pursue or support legal action against you, and we will help to the extent we can if a third party brings action.
To stay in scope, you must:
Out of scope: denial-of-service, social engineering of staff or members, physical attacks, spam, and findings from automated scanners without a demonstrated impact.
04