Responsible Disclosure Program
Security improves when research has a clear path.
If you believe you have found a security vulnerability affecting Nullforge, report it privately. We will review the finding, keep you informed, and work toward a responsible resolution.
Our commitment
We value the researchers who help us see what others might miss.
Nullforge builds security products, but no system should rely on confidence alone. Thoughtful independent research helps us strengthen our products and better protect the organizations, practitioners, and researchers who depend on them.
Product scope
Two products. One responsible path.
This policy covers Nullforge-operated Hive and Swarm services. Swarm lists the definitive scope and exclusions.
Continuous security platform
Hive
Report issues affecting Hive applications, authorized APIs, identity boundaries, and tenant isolation.
Explore Hive →Bug bounty platform
Swarm
Report issues affecting Swarm program, researcher, submission, reward, and tenant workflows.
Explore Swarm →Customer systems, third-party services, and assets not explicitly listed in the Swarm program are not authorized for testing.
Report through Swarm
A secure channel from first signal to final resolution.
Review scope, submit evidence privately, work with triage, and track the report through resolution.
Research policy
Protect people first. Test only what is authorized.
Good-faith research deserves a good-faith response.
When you follow this policy and the scope published in Swarm, Nullforge will treat your research as authorized, work with you to understand and resolve the issue, and will not pursue or recommend legal action for the research. If a third party initiates action related to compliant research, we will make it clear that your work was conducted under this policy.
Minimize impact.
- Use the least invasive method needed to demonstrate the issue.
- Stop when you confirm exposure or encounter non-public data.
- Protect any information you unintentionally access.
- Keep the vulnerability private while we investigate and remediate.
- Follow the current asset scope and testing rules published in Swarm.
Avoid harmful testing.
- No denial of service, destructive testing, or service degradation.
- No social engineering, phishing, physical intrusion, or employee targeting.
- No credential stuffing, password spraying, spam, or high-volume scanning.
- No persistence, lateral movement, data alteration, or unnecessary exfiltration.
- No testing of customer environments or third-party systems without permission.
What makes a report useful.
Reports should describe a reproducible security impact in an in-scope Nullforge asset. Informational observations, automated scanner output without demonstrated impact, and issues requiring unlikely user behavior may be closed without reward.
A strong report
Give our team enough context to reproduce the risk safely.
Redact passwords, tokens, personal information, and customer data.
- Affected product and asset
Identify Hive or Swarm and the exact URL, endpoint, or component.
- Security impact
Explain what an attacker could access, change, or disrupt.
- Reproduction steps
Provide a minimal, reliable sequence our team can follow.
- Supporting evidence
Include sanitized requests, responses, screenshots, or proof-of-concept details.
What happens next
Clear communication through resolution.
Review
We confirm scope and collect any missing context.
Validate
We reproduce the issue and assess its impact.
Remediate
Engineering develops, tests, and deploys the fix.
Coordinate
We share updates and coordinate disclosure when appropriate.
Recognition or monetary rewards, when offered, are governed by the current Swarm program terms and remain at Nullforge’s discretion. Please do not submit the same issue through multiple channels.
Ready to report?
Help us protect the people who rely on Nullforge.
Review the live program scope before testing. For an active vulnerability, submit through Swarm. If Swarm itself is unavailable, email [email protected].
Report through Swarm ↗