Field Assembly LLC
Vulnerability Disclosure Policy
About This Policy
Field Assembly LLC publishes free reference works on its own domains. This policy tells security researchers how to report a vulnerability in one of those sites, what testing we permit, and what we do with a report. It applies to every domain listed under Scope, and each of those domains points to it from its /.well-known/security.txt file.
The sites are static. There are no accounts, no forms, no payments, no user submissions, and no server-side code of ours. That narrows what a vulnerability can be here, and it is why this policy is short.
We do not run a bug bounty program and do not pay for reports. See No Bounty Program before you spend time on a finding in the expectation of a reward.
1. Reporting a Vulnerability
Email [email protected]. That is the only security contact we publish, and it is the address every security.txt in the portfolio names. There is no other intake and no web form.
Where you can, include:
- the affected domain and the full URL;
- a description of the suspected vulnerability;
- steps sufficient for us to reproduce it;
- the potential security impact as you understand it;
- screenshots, request and response details, or other evidence, provided the evidence does not itself expose sensitive information.
Email to us is not end-to-end encrypted and we do not publish an encryption key. If a finding is sensitive enough that this matters, send a first message that says so without the details, and we will work out how to receive them.
You may report anonymously. If you do, we cannot ask follow-up questions or tell you when the issue is resolved.
2. Scope
This policy covers the websites Field Assembly LLC publishes and controls:
- fieldassembly.net and www.fieldassembly.net
- gatheredwork.com
- boardandborder.com
- rulesandrecord.com
- roomandrecourse.com
Authorization under this policy extends only to systems Field Assembly controls, which means the published content of those sites and the configuration we set for them. It does not extend to anything we do not control, even where one of our sites depends on it. That includes:
- Cloudflare, which hosts the sites and terminates their connections, and every other provider of hosting, DNS, domain registration, email, or source control we use;
- the institutions, agencies, and other third-party sites our reference works quote and link to;
- any other service, network, or system operated by someone other than Field Assembly.
Those operators set their own rules for security research. A Field Assembly site using a service does not authorize you to test that service. If you believe a third-party service is exposing one of our sites to a vulnerability, report it to us and to that provider through its own process.
3. Testing Guidelines
Test only as far as needed to show that a vulnerability exists and what its impact is. Once you have that, stop and report it. This policy does not authorize anything beyond that point.
Do not:
- access, acquire, retain, modify, or delete data that does not belong to you;
- attempt to obtain credentials or personal information;
- violate anyone's privacy;
- run destructive tests;
- run denial-of-service or resource-exhaustion tests of any kind;
- use social engineering or phishing against us, our providers, or anyone else;
- test physical security;
- introduce malware or any other malicious code;
- establish persistence or move laterally into other systems;
- run automated activity that materially degrades a site's availability or imposes unreasonable load;
- test third-party systems or services because a Field Assembly site uses them;
- publish a vulnerability before we have had a reasonable opportunity to investigate and address it.
If you come across nonpublic information, or evidence that someone else has gained unauthorized access, stop testing at once and report what you found. Do not examine, copy, or retain it.
4. Coordinated Disclosure
We ask that you give us a reasonable opportunity to investigate and address a legitimate finding before you publish it. We do not set a fixed embargo period, because the right interval depends on the finding. A misconfigured header can be fixed in a day; something that depends on a provider we do not control may take longer, and we will say so.
If you intend to publish, tell us when you report, and tell us again before you do. We will not ask you to withhold publication indefinitely.
5. What to Expect From Us
Field Assembly is a small family business with no dedicated security staff. We review reports as circumstances permit, and we may contact you if we need more information to reproduce or assess a finding.
We do not promise a response within a particular time, a remediation deadline, an acknowledgment, or public credit. We do not maintain a public acknowledgments page. If we fix something you reported and you ask, we will tell you it is fixed.
6. No Bounty Program
Field Assembly does not operate a paid bug bounty program and does not offer compensation for unsolicited vulnerability research or reports.
Nothing in this policy, in a security.txt file, or in our correspondence with you creates an expectation of payment, reward, employment, a contract, or any other consideration. A report is a courtesy, and we treat it as one.
7. Good-Faith Research
If you comply with this policy, Field Assembly LLC treats your research as authorized with respect to the systems it controls, and will not bring a civil claim against you or refer you for prosecution on account of that research. That is the whole of what we can offer, and it is conditioned on compliance with every part of this policy.
It is limited in ways you should understand before you rely on it. We can authorize only what we control; we cannot authorize testing of any third party's systems, waive rights that belong to anyone else, or bind any government authority. We make no representation about how any law applies to your research. If you are unsure whether something is within this policy, ask before you do it.
This is an operational policy for a public website. It is not legal advice.
8. Changes
We may revise this policy. The dates at the top of this page show when it took effect and when it last changed. The version published at fieldassembly.net/legal/vulnerability-disclosure governs, and each site's security.txt names that address.
9. Contact
Security reports and questions about this policy: [email protected].
Field Assembly LLC, Massachusetts, United States.