Vulnerability Disclosure Policy
1. We want good-faith reports
If you find a security issue in AgileFlex / FANMS (web apps, APIs, or related infrastructure we operate), please tell us privately so we can fix it before it is abused.
2. How to report
Email fuelingagilenigeria@gmail.com with:
- A short description of the issue
- Steps to reproduce (or a proof-of-concept that does not destroy data)
- Affected URL / endpoint / role used
- Your contact details
- Whether you plan any public disclosure and when
We will acknowledge reports when practical and keep you updated on remediation status.
3. Safe harbour (good faith)
If you:
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
- Do not exploit the issue beyond what is needed to demonstrate it
- Do not access data that is not yours
- Give us a reasonable time to fix before public disclosure
…we will not pursue legal action for that research against you for the report itself.
This safe harbour does not cover attacks that steal data, interrupt service, or pivot into unrelated systems.
4. Out of scope (examples)
- Social engineering of our staff or customers
- Physical attacks
- Denial-of-service / volumetric flooding
- Reports from automated scanners with no demonstrated impact
- Issues only present on third-party sites we do not control
- Missing best-practice headers without a workable exploit path
5. Rewards
We may thank researchers publicly (with permission). A paid bug bounty is not guaranteed unless we announce one separately.
6. Please do not
- Demand ransom
- Modify or delete customer data
- Use findings to access other tenants’ data
- Publicly post exploit details before we confirm a fix (or before an agreed disclosure date)