Legal

Security Policy

How to report security vulnerabilities and our commitment to security.

Our Commitment

Security is fundamental to macfor's mission. As a forensic tool, macfor must be trustworthy—both in how it handles evidence and in its own security posture. We take security vulnerabilities seriously and appreciate the security research community's efforts to responsibly disclose issues.

Reporting a Vulnerability

If you discover a security vulnerability in macfor, please report it to us privately:

Email: security@macfor.io

PGP Key: Available on request — contact our security team

What to Include

Please provide:

  1. Description: Clear explanation of the vulnerability
  2. Impact: What an attacker could achieve
  3. Steps to Reproduce: Detailed instructions to reproduce the issue
  4. Affected Versions: Which versions are impacted
  5. Suggested Fix: If you have one (optional)

What to Expect

  • Acknowledgement: Within 48 hours
  • Initial Assessment: Within 7 days
  • Regular Updates: At least weekly during investigation
  • Fix Timeline: Depends on severity (see below)
  • Credit: Public acknowledgement (unless you prefer anonymity)

Severity Levels and Response Times

SeverityDescriptionTarget Fix Time
CriticalRemote code execution, evidence tampering24-48 hours
HighPrivilege escalation, data exposure7 days
MediumLimited impact vulnerabilities30 days
LowMinor issues, hardening opportunities90 days

Scope

In Scope

  • macfor Collector (all editions)
  • macfor Analyze (when released)
  • macfor.io website
  • Official documentation
  • Build and release infrastructure

Out of Scope

  • Third-party dependencies (report to upstream)
  • Social engineering attacks
  • Physical security issues
  • Denial of service attacks
  • Issues requiring physical access to target system

Safe Harbour

We support responsible security research. When conducted in good faith:

  • We will not pursue legal action
  • We will work with you to understand and resolve issues
  • We will credit researchers who report valid vulnerabilities

To qualify for safe harbour:

  • Make a good faith effort to avoid privacy violations, data destruction, and service disruption
  • Don't access or modify other users' data
  • Stop testing and report immediately upon discovering a vulnerability
  • Don't disclose the vulnerability publicly before we've addressed it

Security Practices

Development

  • Code review required for all changes
  • Static analysis (golangci-lint) on every commit
  • Dependency scanning for known vulnerabilities
  • Signed releases with checksums

Infrastructure

  • HTTPS everywhere
  • Regular security updates
  • Access logging and monitoring
  • Principle of least privilege

Evidence Handling

macfor is designed with evidence security in mind:

  • No telemetry or phone-home functionality
  • Evidence never leaves the local system
  • SHA-256 hashing for integrity verification
  • Chain of custody documentation

Vulnerability Disclosure Policy

We follow coordinated vulnerability disclosure:

  1. Reporter submits vulnerability to security@macfor.io
  2. macfor acknowledges and investigates
  3. macfor develops and tests fix
  4. macfor releases fix and publishes advisory
  5. Reporter may publish details after fix is available

We request a 90-day disclosure window for most vulnerabilities, extendable for complex issues.

Security Advisories

Security advisories are published at:

Subscribe to our security mailing list for notifications: security-announce@macfor.io

Bug Bounty

We don't currently offer a formal bug bounty program. However, we recognise significant contributions with:

  • Public acknowledgement (with permission)
  • macfor swag
  • Free Professional licenses for researchers

Contact

Thank you for helping keep macfor and its users secure.