Security & responsible disclosure

If you have found a security issue in FairlyRemote, we want to hear about it. This page explains how to report it, what to expect from us, and the safe-harbor terms that protect good-faith research.

Last updated: 4 July 2026 Policy referenced by our security.txt

Reporting a vulnerability

Found something? Here’s how to tell us.

Report security issues by email rather than public GitHub issues, social media, or other public channels, so we can fix the problem before it is widely known.

1

Email the details

Send your report to security@fairlyremote.com.

2

Include what makes it actionable

  • The type of issue and the component or URL affected.
  • Step-by-step instructions to reproduce it, including any proof-of-concept.
  • The impact you believe it has, and any suggested remediation.
  • Whether you would like to be credited if we publish a fix.
What you can expect from us

A clear response, on a clock.

Acknowledgement in 48 hours

Of your report reaching security@fairlyremote.com.

Triage & a remediation plan

An assessment and, where we accept the report, a plan to fix it.

Fix targeted in 14 days

For high-severity issues. Lower severity is scheduled by risk; we keep you informed either way.

Credit if you’d like it

In our disclosure notes, when the report led to a fix.

We are a small independent team (a service of Meourobo Labs Ltd), so we do not currently run a paid bug-bounty programme. We are grateful for responsible reports and will acknowledge researchers who help us.

Safe harbor

Good-faith research is authorised.

We will not pursue or support legal action against you for security research conducted in good faith and in accordance with this policy.

Specifically, if you:

  • make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our service;
  • only access, or attempt to access, accounts and data that belong to you (for example, test accounts you create), and do not access, modify, or exfiltrate other users’ data;
  • do not run denial-of-service tests, high-volume automated scanning, spam, or social-engineering / phishing against our staff or customers;
  • give us a reasonable time to investigate and remediate before disclosing publicly; and
  • do not exploit an issue beyond the minimum necessary to demonstrate it,

then we consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not recommend or pursue legal action related to your report. If legal action is initiated by a third party against you for activity that was conducted in accordance with this policy, we will make this authorisation known. This is not a licence to access data belonging to other people, and it does not waive any rights of third parties.

Scope

What’s in scope, and what isn’t.

In scope

The FairlyRemote web application (app.fairlyremote.com), the marketing site (fairlyremote.com), and our APIs.

Out of scope

Our sub-processors’ own infrastructure (Supabase, Stripe, Google, Microsoft, Fly.io, Cloudflare, Sentry, Resend, Plausible, Crisp); report those to the respective vendor. Also out of scope: findings that require physical access to a user’s device, and reports that are purely theoretical without a demonstrated impact.

Security posture

How we protect the data we hold.

TLS 1.3 in transit
Encryption at rest
Postgres row-level security
Short-lived tokens
Dependency scanning
PII scrubbing in logs

What we don’t claim

We are not SOC 2 or ISO 27001 certified, and the product is not designed to handle PHI / HIPAA. For the full posture see the Security section of our Trust page. Our data-handling commitments are in the Privacy Policy, including how we notify customers of a data breach (within 72 hours of becoming aware).

Questions about this policy? Email security@fairlyremote.com.