Surfil
// Trust center

Responsible disclosure

Surfil's security depends on people who report issues rather than exploit them. Here is how to reach us, what is in scope, and the good-faith safe harbour you can rely on.

Last updated 2026-07-11

1.How to report

Email security@surfil.com with a clear description and the steps to reproduce. Encrypt sensitive detail if you can; we will confirm receipt and open a tracked conversation with you.

2.What to include

The affected surface, a reproduction, the impact you believe it has, and anything you ran to demonstrate it. Concrete, reproducible reports get triaged fastest.

3.Scope

Surfil's own web app, edge API and runtime are in scope. Third-party subprocessors, denial-of-service, social engineering and physical attacks are out of scope; report platform issues to the relevant vendor.

4.Our commitment

We acknowledge reports quickly, keep you updated as we triage and fix, and will not pursue action against good-faith research that follows this policy. We do not currently run a paid bounty.

5.Safe harbour

If you make a good-faith effort to follow this policy - avoid privacy violations and data destruction, stay within scope, and give us reasonable time to fix - we consider your research authorized and will not pursue legal action.

6.Recognition

With your consent, we credit reporters once an issue is resolved. Honest, coordinated disclosure is exactly the behaviour a signed-proof security product should reward.

This is illustrative structure and posture, not final reviewed legal wording.

More in the Trust Center