FAULTLINE

Security & Responsible Disclosure

Last updated 2026-07-15 · Machine-readable at /.well-known/security.txt (RFC 9116)

We take the security of FaultLine — and of the memory our customers entrust to it — seriously. If you believe you've found a security vulnerability, we want to hear from you, and we'll work with you to understand and resolve it quickly. This page is our coordinated vulnerability disclosure (CVD) policy.

Report a vulnerability

Email security@volenti.ca. Please include enough detail to reproduce: the affected URL/endpoint, a description of the issue and its impact, and step-by-step reproduction (proof-of-concept, request/response snippets, or a short screen capture). If the report is sensitive, say so and we'll arrange an encrypted channel.

Scope

In scope: faultline.ca, app.faultline.ca, and the FaultLine memory engine, MCP surface, and customer consoles served there.

Out of scope (please don't test these):

Safe harbor

We authorize good-faith security research conducted in accordance with this policy. If you make a good-faith effort to comply with it, we will consider your research authorized, we will not pursue or support legal action against you for it, and we will work with you to resolve the issue. Good faith means: you avoid privacy violations and service disruption, you only interact with accounts and data you own or have explicit permission to test, and you give us a reasonable opportunity to fix the issue before disclosing it publicly.

What to expect from us

Handling of memory & personal data

FaultLine isolates each customer's memory in its own per-tenant store. If your research incidentally exposes personal data or another party's memory, stop, do not save or share it, and tell us immediately in your report so we can contain it. We will treat any such exposure as a priority.

⊢ FAULTLINE · WRITE-VALIDATED MEMORY · Home · security.txt · Terms · Made by Volenti