Two software researchers reviewing code at their workstations

Responsible Disclosure Program

Security improves when research has a clear path.

If you believe you have found a security vulnerability affecting Nullforge, report it privately. We will review the finding, keep you informed, and work toward a responsible resolution.

Our commitment

We value the researchers who help us see what others might miss.

Nullforge builds security products, but no system should rely on confidence alone. Thoughtful independent research helps us strengthen our products and better protect the organizations, practitioners, and researchers who depend on them.

Product scope

Two products. One responsible path.

This policy covers Nullforge-operated Hive and Swarm services. Swarm lists the definitive scope and exclusions.

Continuous security platform

Hive

Report issues affecting Hive applications, authorized APIs, identity boundaries, and tenant isolation.

Explore Hive

Bug bounty platform

Swarm

Report issues affecting Swarm program, researcher, submission, reward, and tenant workflows.

Explore Swarm

Customer systems, third-party services, and assets not explicitly listed in the Swarm program are not authorized for testing.

Report through Swarm

A secure channel from first signal to final resolution.

Review scope, submit evidence privately, work with triage, and track the report through resolution.

Two software engineers working at adjacent development stations
Research handled by people, supported by a secure workflow.
ScopeConfirm the asset
SubmitShare the evidence
CollaborateWork with triage
ResolveCoordinate disclosure

Research policy

Protect people first. Test only what is authorized.

Safe harbor

Good-faith research deserves a good-faith response.

When you follow this policy and the scope published in Swarm, Nullforge will treat your research as authorized, work with you to understand and resolve the issue, and will not pursue or recommend legal action for the research. If a third party initiates action related to compliant research, we will make it clear that your work was conducted under this policy.

Do

Minimize impact.

  • Use the least invasive method needed to demonstrate the issue.
  • Stop when you confirm exposure or encounter non-public data.
  • Protect any information you unintentionally access.
  • Keep the vulnerability private while we investigate and remediate.
  • Follow the current asset scope and testing rules published in Swarm.
Do not

Avoid harmful testing.

  • No denial of service, destructive testing, or service degradation.
  • No social engineering, phishing, physical intrusion, or employee targeting.
  • No credential stuffing, password spraying, spam, or high-volume scanning.
  • No persistence, lateral movement, data alteration, or unnecessary exfiltration.
  • No testing of customer environments or third-party systems without permission.
Eligibility

What makes a report useful.

Reports should describe a reproducible security impact in an in-scope Nullforge asset. Informational observations, automated scanner output without demonstrated impact, and issues requiring unlikely user behavior may be closed without reward.

A strong report

Give our team enough context to reproduce the risk safely.

Redact passwords, tokens, personal information, and customer data.

  1. Affected product and asset

    Identify Hive or Swarm and the exact URL, endpoint, or component.

  2. Security impact

    Explain what an attacker could access, change, or disrupt.

  3. Reproduction steps

    Provide a minimal, reliable sequence our team can follow.

  4. Supporting evidence

    Include sanitized requests, responses, screenshots, or proof-of-concept details.

What happens next

Clear communication through resolution.

Review

We confirm scope and collect any missing context.

Validate

We reproduce the issue and assess its impact.

Remediate

Engineering develops, tests, and deploys the fix.

Coordinate

We share updates and coordinate disclosure when appropriate.

Recognition or monetary rewards, when offered, are governed by the current Swarm program terms and remain at Nullforge’s discretion. Please do not submit the same issue through multiple channels.

Ready to report?

Help us protect the people who rely on Nullforge.

Review the live program scope before testing. For an active vulnerability, submit through Swarm. If Swarm itself is unavailable, email [email protected].

Report through Swarm

Talk to us

Tell us what you’re trying to protect.

We’ll connect your inquiry with the right Nullforge team and respond within one business day.

Share enough context for us to route your inquiry. Maximum 1,500 characters.

Protected by Cloudflare Turnstile. No website account is required.