Security
Security & Disclosure
FentWare is a small private homelab environment, but security reports are taken seriously. Security disclosures use the same private support ticket system as other FentWare requests.
Reporting a problem
Submit security reports through the FentWare support form. Include the affected URL or service, a clear description of the issue, and enough reproduction detail for us to verify it. Reports submitted there are stored privately and are only visible to authorized FentWare administrators.
Our machine-readable security contact is published at /.well-known/security.txt.
Good-faith testing
- Do not access, alter, download, or destroy data belonging to other users.
- Do not perform denial-of-service, destructive testing, spam, credential stuffing, or social engineering.
- Do not intentionally disrupt services or attempt to pivot into unrelated systems.
- Use the minimum testing necessary to demonstrate a suspected issue.
Credentials
FentWare credential forms are intended only for FentWare accounts. We do not use our login pages to collect passwords for unrelated third-party accounts.
Scope
This page covers services operated under the FentWare domain and infrastructure we control. Third-party services linked from FentWare remain subject to their own security policies.
