Legal
Security Policy
How to report security vulnerabilities and our commitment to security.
Our Commitment
Security is fundamental to macfor's mission. As a forensic tool, macfor must be trustworthy—both in how it handles evidence and in its own security posture. We take security vulnerabilities seriously and appreciate the security research community's efforts to responsibly disclose issues.
Reporting a Vulnerability
If you discover a security vulnerability in macfor, please report it to us privately:
Email: security@macfor.io
PGP Key: Available on request — contact our security team
What to Include
Please provide:
- Description: Clear explanation of the vulnerability
- Impact: What an attacker could achieve
- Steps to Reproduce: Detailed instructions to reproduce the issue
- Affected Versions: Which versions are impacted
- Suggested Fix: If you have one (optional)
What to Expect
- Acknowledgement: Within 48 hours
- Initial Assessment: Within 7 days
- Regular Updates: At least weekly during investigation
- Fix Timeline: Depends on severity (see below)
- Credit: Public acknowledgement (unless you prefer anonymity)
Severity Levels and Response Times
| Severity | Description | Target Fix Time |
|---|---|---|
| Critical | Remote code execution, evidence tampering | 24-48 hours |
| High | Privilege escalation, data exposure | 7 days |
| Medium | Limited impact vulnerabilities | 30 days |
| Low | Minor issues, hardening opportunities | 90 days |
Scope
In Scope
- macfor Collector (all editions)
- macfor Analyze (when released)
- macfor.io website
- Official documentation
- Build and release infrastructure
Out of Scope
- Third-party dependencies (report to upstream)
- Social engineering attacks
- Physical security issues
- Denial of service attacks
- Issues requiring physical access to target system
Safe Harbour
We support responsible security research. When conducted in good faith:
- We will not pursue legal action
- We will work with you to understand and resolve issues
- We will credit researchers who report valid vulnerabilities
To qualify for safe harbour:
- Make a good faith effort to avoid privacy violations, data destruction, and service disruption
- Don't access or modify other users' data
- Stop testing and report immediately upon discovering a vulnerability
- Don't disclose the vulnerability publicly before we've addressed it
Security Practices
Development
- Code review required for all changes
- Static analysis (golangci-lint) on every commit
- Dependency scanning for known vulnerabilities
- Signed releases with checksums
Infrastructure
- HTTPS everywhere
- Regular security updates
- Access logging and monitoring
- Principle of least privilege
Evidence Handling
macfor is designed with evidence security in mind:
- No telemetry or phone-home functionality
- Evidence never leaves the local system
- SHA-256 hashing for integrity verification
- Chain of custody documentation
Vulnerability Disclosure Policy
We follow coordinated vulnerability disclosure:
- Reporter submits vulnerability to security@macfor.io
- macfor acknowledges and investigates
- macfor develops and tests fix
- macfor releases fix and publishes advisory
- Reporter may publish details after fix is available
We request a 90-day disclosure window for most vulnerabilities, extendable for complex issues.
Security Advisories
Security advisories are published at:
Subscribe to our security mailing list for notifications: security-announce@macfor.io
Bug Bounty
We don't currently offer a formal bug bounty program. However, we recognise significant contributions with:
- Public acknowledgement (with permission)
- macfor swag
- Free Professional licenses for researchers
Contact
- Security Reports: security@macfor.io
- General Security Questions: security@macfor.io
- PGP Key: Available on request via security@macfor.io
Thank you for helping keep macfor and its users secure.