Responsible disclosure
Surfil's security depends on people who report issues rather than exploit them. Here is how to reach us, what is in scope, and the good-faith safe harbour you can rely on.
Last updated 2026-07-11
1.How to report
Email security@surfil.com with a clear description and the steps to reproduce. Encrypt sensitive detail if you can; we will confirm receipt and open a tracked conversation with you.
2.What to include
The affected surface, a reproduction, the impact you believe it has, and anything you ran to demonstrate it. Concrete, reproducible reports get triaged fastest.
3.Scope
Surfil's own web app, edge API and runtime are in scope. Third-party subprocessors, denial-of-service, social engineering and physical attacks are out of scope; report platform issues to the relevant vendor.
4.Our commitment
We acknowledge reports quickly, keep you updated as we triage and fix, and will not pursue action against good-faith research that follows this policy. We do not currently run a paid bounty.
5.Safe harbour
If you make a good-faith effort to follow this policy - avoid privacy violations and data destruction, stay within scope, and give us reasonable time to fix - we consider your research authorized and will not pursue legal action.
6.Recognition
With your consent, we credit reporters once an issue is resolved. Honest, coordinated disclosure is exactly the behaviour a signed-proof security product should reward.
This is illustrative structure and posture, not final reviewed legal wording.