01
Responsible Disclosure Policy
First Decree's responsible disclosure policy is built on the disclose.io vulnerability disclosure framework. Security sits at the core of how we operate, and we rely on the good-faith work of security researchers to help us hold a high standard for the safety and privacy of everyone who trusts us with their data. This policy defines what we consider good-faith research and reporting, and lays out exactly what you can expect from us once you've submitted a finding.
02
Reporting
To report a potential security issue or vulnerability in our products or infrastructure, follow this process:
- Document the issue thoroughly. Compile all relevant technical detail — a clear description of the vulnerability, step-by-step reproduction instructions, and any supporting evidence (logs, screenshots, proof-of-concept code) that helps us validate and act on your finding quickly.
- Submit your report through an official channel. Open a ticket on our Discord server, or email us directly at security@firstdecree.org. Do not disclose the issue publicly or to third parties before we've had the opportunity to review and address it.
- Expect a response within 2 business days. We treat every submission seriously and will confirm receipt of your report within this window, followed by regular updates as we investigate and remediate.
We take every report seriously, and we're committed to working alongside the security community — not against it — to keep our systems and our users safe.