Security policy

Version 1.2 · Last updated: June 9, 2026 · Operator: Furx (INVERSO HUB S.R.L.)

Reporting a vulnerability

If you believe you have found a security vulnerability in Furx (desktop app, the license API, or the public site), please report it to security@furx.cloud. We aim to acknowledge reports within 2 business days and to provide a remediation timeline within 5 business days.

Encrypt sensitive reports with our PGP key (fingerprint published in /.well-known/security.txt).

What to include

Coordinated disclosure

We follow a coordinated-disclosure model with a 90-day embargo from acknowledgement. We commit to:

Reward programme

Furx is bootstrapped, so we don't have a cash bounty programme. We offer:

Out of scope

Security controls in place

Trust signals

Known accepted risks (transparency)

Hall of fame

Open. Be the first.

Questions? Write to legal@furx.cloud. Privacy: dpo@furx.cloud.