Security · Vulnerability reporting

Vulnerability Reporting

last updated 2026-08-02 · responsible disclosure, not a bounty program

01

Who handles this

Decisionlore is operated by Freemansland Creatives Pte Ltd (UEN 202321157G), a small team, not a security vendor with a dedicated incident-response desk. We take reports seriously and read every one ourselves. We do not currently run a paid bug bounty program; this page describes our responsible-disclosure process, not a bounty.

02

Scope

In scope:

  • Decisionlore's web application (decisionlore.com and its subdomains)
  • The Decisionlore API the web application talks to
  • Anything that would let one workspace read, modify, or delete another workspace's data, or bypass authentication, authorization, or the row-level security described on our Security page

Out of scope:

  • Our sub-processors' own infrastructure (Supabase, Anthropic, Voyage AI, Stripe, and similar): report those directly to the provider
  • Denial-of-service or load/stress testing, spam, or automated scanning that degrades the service for real customers
  • Social engineering, phishing, or physical attacks against us or our customers
  • Reports that require a customer's own compromised device or credentials rather than a flaw in Decisionlore itself
  • Missing security headers, cookie flags, or other best-practice notes with no demonstrated impact
03

What to send us

Email nick@freemanslandcreatives.com with:

  • The affected URL or endpoint
  • Steps to reproduce, as exact as you can make them
  • What the impact is (what an attacker could actually do with it)
  • Any proof-of-concept request, script, or screenshot that demonstrates it, without going further than needed to prove it

If you can encrypt sensitive details, mention that in your first email and we will arrange a way to receive them; otherwise plain email is fine for most reports.

04

What happens after you report

We acknowledge new reports within one business day, the same commitment on our Security page. From there, timelines depend honestly on severity and complexity: a critical tenant-isolation or authentication bypass gets fixed fastest, a low-severity finding may take longer while we work through it alongside everything else a small team is running. We will tell you when we've fixed it and are glad to credit you (with your permission) once a fix has shipped.

05

Safe harbor

If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue legal action against you for that research. Good faith means:

  • You stop and report as soon as you've confirmed a vulnerability, rather than continuing to explore how far it goes
  • You only access, download, or modify the minimum data needed to demonstrate the issue, and never another real customer's data beyond what's unavoidable to prove impact
  • You give us a reasonable chance to fix the issue before any public disclosure
  • You don't use the vulnerability for anything beyond verifying and reporting it, including extortion or demanding payment

This safe harbor doesn't extend to third-party systems (see Scope above); we can only make this commitment for Decisionlore itself.

06

Contact

nick@freemanslandcreatives.com. See also the Security page for our technical controls and Data Protection for how personal data is handled.