Last updated: July 11, 2025
FireWatcher is committed to maintaining the highest standards of security. We welcome and encourage security researchers and the broader community to help us identify and address potential vulnerabilities in our systems and services.
This programme covers vulnerabilities in:
Reports must demonstrate a credible security breach with actual exploitability. Mere missing of security best practices without demonstrable impact will not be entertained.
When reporting a vulnerability, please include:
Within 24 hours of receiving your report
Every 72 hours until resolution
Our target resolution times:
We ask that you:
FireWatcher will not pursue legal action against security researchers who:
The following are not considered vulnerabilities:
FireWatcher provides monetary rewards for valid vulnerability reports based on the CVSS score and our internal security assessment. Reward amounts are determined by the severity and impact of the vulnerability discovered.
Reward tiers are based on:
We may update this vulnerability disclosure programme from time to time. Changes will be posted on this page with an updated revision date. We encourage you to review this page periodically for any updates.
For critical security issues that require immediate attention, please contact our security team directly at security@firewatcher.ai with “URGENT SECURITY ISSUE” in the subject line.