Security & Vulnerability Disclosure Policy
Effective Date: June 18, 2026
Company: Freedom Labs LTD
1. Reporting a Vulnerability
If you believe you have found a security vulnerability in any Freed Finance property (including freed.finance, freed.fi, and api.freed.finance), please report it to us responsibly at security@freed.finance.
Please include a clear description, reproduction steps, affected URLs/endpoints, and any proof-of-concept. Do not include real user data, and do not publicly disclose the issue until we have resolved it.
2. Our Commitment
- Acknowledge receipt of your report within 48 hours.
- Provide a status update at least every 7 days.
- Work to validate and remediate confirmed issues promptly.
- Credit researchers who follow this policy, where they wish to be named.
3. Safe Harbor
We will not pursue or support legal action against researchers who act in good faith, comply with this policy, avoid privacy violations and service degradation, and give us a reasonable opportunity to remediate before any public disclosure.
4. Out of Scope
- Findings from automated scanners without a demonstrable impact.
- Denial-of-service (DoS/DDoS) and volumetric testing.
- Social engineering, phishing, or physical attacks against staff.
- Vulnerabilities in third-party services we do not control, except where they directly impact Freed Finance users.
Machine-readable disclosure metadata is published at /.well-known/security.txt per RFC 9116.