Where to send the report
Use security@heartboat.me or choose Security in the private contact form. Website security tickets are separated from ordinary support and require the security role. For an issue in FP or Integritellent source, check that repository’s security instructions; do not publish exploit details in an Issue or community thread.
What makes a report useful
Describe the affected domain and route, the date, source or release version if known, the behavior you observed and the potential impact. Include the minimum safe reproduction steps, a redacted request ID or log, and what you expected instead. Use your own account or test data; do not attach a private key, live token or someone else’s private record.
Testing and disclosure
A private reporting channel is not permission to access other accounts, extract private data, disrupt service or perform unbounded scanning. Stop once you have enough safe evidence. Discuss publication of the details with the maintainer so a report does not expose participants before the issue has been addressed. No bounty or fixed response time is promised.
Receipt, delivery and reply
The form gives you a private receipt when the ticket is stored. Email notification delivery and operator replies are separate states; a receipt is not a claim that the report has been reviewed. Keep the receipt secret and use it to check updates. General outages can be checked on the public status page.
Reporting guidance
Our private reporting instructions follow GitHub’s guidance to publish a security policy and provide a private contact channel. They do not assert that GitHub private vulnerability reporting or a staffed security team is enabled for every project.
