Ir para o conteúdo
FortiSafe VPN

Security and vulnerability reporting

Found a security issue in FortiSafe? Write to [email protected]. We read every report and reply from the same address. There's no bug bounty programme.

Report an issue

How to report

  • What happens and where: the affected address, screen or app.
  • Steps to reproduce it.
  • The impact you observed.
  • A way to reach you so we can follow up.

You can write in English, Portuguese or Spanish.

Rules for testing

  • Only use your own account.
  • Don't access, change or delete other people's data. If you come across someone's data, stop and tell us.
  • No denial-of-service attacks or load testing.
  • No social engineering, phishing or contacting customers and staff.
  • No intrusive testing of the VPN servers: they're run by an infrastructure partner, and we can't authorise testing on their systems.
  • Allow time for a fix before disclosing the issue.

Having this channel and a security.txt file isn't, on its own, permission to test.

What already protects your account

  • Passwordless sign-in: a 6-digit code sent by email, valid for 10 minutes, with up to 5 attempts and at most 5 codes per hour.
  • The code and the session token are stored only as hashes: a database leak doesn't turn into access.
  • On the web, the session lives in an HttpOnly, Secure, SameSite=Lax cookie and lasts up to 90 days.
  • The VPN tunnel uses WireGuard.
  • The website and API force browsers to use encrypted connections (HSTS), and the website only runs its own scripts (Content-Security-Policy), which makes injecting third-party code harder.
  • What we log, and for how long, is published on our What we log page.

What we don't have yet

  • A bug bounty programme.
  • A PGP key for encrypted reports.
  • A published independent audit.

security.txt

The contact is also in /.well-known/security.txt, following RFC 9116, here and on api.fortisafe.net. /.well-known/security.txt