Security & Responsible Disclosure
Last updated 2026-07-15 · Machine-readable at /.well-known/security.txt (RFC 9116)
We take the security of FaultLine — and of the memory our customers entrust to it — seriously. If you believe you've found a security vulnerability, we want to hear from you, and we'll work with you to understand and resolve it quickly. This page is our coordinated vulnerability disclosure (CVD) policy.
Report a vulnerability
Email security@volenti.ca. Please include enough detail to reproduce: the affected URL/endpoint, a description of the issue and its impact, and step-by-step reproduction (proof-of-concept, request/response snippets, or a short screen capture). If the report is sensitive, say so and we'll arrange an encrypted channel.
Scope
In scope: faultline.ca, app.faultline.ca, and the
FaultLine memory engine, MCP surface, and customer consoles served there.
Out of scope (please don't test these):
- Denial-of-service, volumetric, or resource-exhaustion testing of any kind.
- Social engineering, phishing, or physical attacks against our people or facilities.
- Automated scanner output with no demonstrated, reproducible impact.
- Third-party services we depend on (report those to the respective vendor).
- Findings that require a compromised account/device you don't own, or that access, modify, or exfiltrate another tenant's or user's data.
Safe harbor
We authorize good-faith security research conducted in accordance with this policy. If you make a good-faith effort to comply with it, we will consider your research authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue. Good faith means: you avoid privacy violations and service disruption, you only interact with accounts and data you own or have explicit permission to test, and you give us a reasonable opportunity to fix the issue before disclosing it publicly.
What to expect from us
- We aim to acknowledge your report within 3 business days.
- We'll keep you updated on our progress and triage, and let you know when it's resolved.
- We practice coordinated disclosure — we ask that you give us a reasonable window (typically up to 90 days) to remediate before any public disclosure, and we're happy to coordinate timing and credit with you.
Handling of memory & personal data
FaultLine isolates each customer's memory in its own per-tenant store. If your research incidentally exposes personal data or another party's memory, stop, do not save or share it, and tell us immediately in your report so we can contain it. We will treat any such exposure as a priority.