SecurityResponsible disclosure
FELSITE · 2026

Found something?
We want to hear it

We build security hardware. It would be strange not to have a front door for security reports.

01 · Where to send it

security@felsite.com

Email security@felsite.com with enough detail to reproduce the issue. If you would prefer to encrypt it, say so and we will exchange keys before you send anything sensitive.

This address covers this website and our public infrastructure. Findings in our upstream open-source contributions should go to the relevant project’s own security process, which will usually get them fixed faster.

02 · What we commit to

Acknowledgement, and an honest answer

  • We acknowledge a report within five working days.
  • We tell you whether we consider it valid, and why, rather than going silent.
  • We keep you updated while we fix it, and we agree timing with you before anything is published.
  • We will credit you when a fix ships, unless you would rather we did not.

We do not currently run a paid bounty. We will say so plainly rather than imply one.

03 · What we ask

Good-faith testing only

Please do not access, modify or delete data that is not yours, degrade our services, or test the physical security of any premises. Testing that stays within those lines and is reported to us in good faith is welcome, and we will not pursue action over it.

Machine-readable version: /.well-known/security.txt