Frameleaf welcomes good-faith reports of security vulnerabilities. This Policy explains our security boundaries, how to report a problem, the research we authorize and how we respond. The Security, Retention and Deletion Schedule and applicable Data Processing Addendum state our contractual security and incident obligations. This Policy does not create an additional uptime or recovery guarantee.
1. Reporting a vulnerability or security incident
Report privately to [email protected], with “Security report” in the subject, or contact us through https://frameleaf.app. You do not need a paid account to report an issue. For suspected active compromise, indicate that clearly in the subject and describe the immediate risk.
Please include:
- The affected product, hostname, endpoint or software version.
- A concise description, reproducible steps and the security impact you believe is possible.
- The time of the observation, preferably in UTC, and relevant request identifiers.
- A minimal demonstration using your own accounts and test data, with sensitive values removed.
- A safe contact method and whether you wish to receive public credit.
Do not send usable credentials, private keys, full payment-card details, unrelated personal data or unnecessary private media. If a report needs sensitive evidence, first ask us to arrange an appropriate secure transfer method. Do not put exploit details in a public issue before coordinated disclosure.
For a compromised customer account, preserve relevant records, stop exposing affected credentials and contact support. Do not destroy your only recovery copy while attempting to contain an incident.
2. Security boundaries
Frameleaf Library runs on infrastructure controlled by its administrator. That administrator is responsible for the host, network, updates, permissions, local database and source media. Frameleaf Cloud provides separate account, connectivity, managed backup and selected processing services. It is not a hosted replacement for the running Library.
Remote-access relay forwards the encrypted TLS session to the Library without decrypting its application payload. Routing hostnames, connection information and usage measurements remain visible. Cloud account, identity and API services process the requests sent to those separate endpoints.
Managed Cloud Backup uses storage-provider server-side encryption with customer-provided keys. The Library sends the key over HTTPS to the storage endpoint for content operations; the processor performs encryption and decryption. The Cloud coordination service does not receive the usable bucket key through the ordinary backup protocol. Optional escrow stores a passphrase-wrapped envelope. This is not a claim that the storage processor never receives a usable key or readable content.
Buddy Backup encrypts recovery blocks and metadata on the source before transfer to a paired customer-operated server. Cloud coordinates authorization and connections. Confidentiality protection does not guarantee that a peer stays online or retains its disks, and a lost recovery key can make intact data unreadable.
Cloud AI processes readable selected inputs at its authorized processing system. Depending on the selected job, those inputs can include prepared previews, full images, video or audio. Selected AI content is uploaded directly to an ephemeral processing worker. Uploaded content and container-local working data are deleted immediately when the job finishes, and the processing container is destroyed. Frameleaf does not retain a stopped container or a separate post-job upload archive. The destroyed container and its uploaded content cannot be recovered through the service. Cloud AI also requires its own authorization. Backup or relay activation is not authorization for AI analysis.
Frameleaf will apply reasonable access controls, administrative authentication, logging, credential protection and incident handling within its responsibility. Encryption does not protect against every compromised endpoint, authorized administrator, stolen session or lost key. We do not assert a certification or an absolute security guarantee through this Policy.
3. Authorized Cloud research scope
Subject to the rules below, research is authorized against the following Frameleaf-operated services when they are active and under Frameleaf’s control:
frameleaf.cloud, the account site, and itsaccount.frameleaf.cloudredirect.id.frameleaf.cloud, the identity service.api.frameleaf.cloud, the Cloud API, including backup provisioning, credentials, usage, recovery and lifecycle operations.- The regional backup endpoints listed below, within the backup-specific authorization described here.
ml.eu.frameleaf.cloudandml.na.frameleaf.cloud, where the regional processing endpoint is enabled.- Frameleaf-operated relay infrastructure under
*.relays.frameleaf.cloudand Frameleaf-operated authoritative name servers forframeleaf.net. status.frameleaf.cloud, to the extent operated and controlled by Frameleaf.
Regional backup endpoints
The following Frameleaf backup hostnames are included for research into Frameleaf-controlled DNS configuration, service integration, credential scoping and access controls, using only your own authorized test accounts, buckets and data:
s3.ap-northeast-1.backup.frameleaf.cloud.s3.ap-northeast-2.backup.frameleaf.cloud.s3.ap-southeast-1.backup.frameleaf.cloud.s3.ap-southeast-2.backup.frameleaf.cloud.s3.ca-central-1.backup.frameleaf.cloud.s3.eu-central-1.backup.frameleaf.cloud.s3.eu-central-2.backup.frameleaf.cloud.s3.eu-south-1.backup.frameleaf.cloud.s3.eu-west-1.backup.frameleaf.cloud.s3.eu-west-2.backup.frameleaf.cloud.s3.eu-west-3.backup.frameleaf.cloud.s3.us-central-1.backup.frameleaf.cloud.s3.us-east-1.backup.frameleaf.cloud.s3.us-east-2.backup.frameleaf.cloud.s3.us-west-1.backup.frameleaf.cloud.s3.us-west-2.backup.frameleaf.cloud.
These hostnames are DNS-only aliases maintained in Frameleaf’s Cloudflare DNS zone and route to the storage provider; their inclusion does not mean Cloudflare proxies or stores backup content. Associated _acme-challenge records may be examined through ordinary public DNS queries to assess Frameleaf’s configuration. They are certificate-validation records, not additional storage endpoints.
This authorization covers the Frameleaf-controlled aspects of the backup service. It does not authorize attacks on the storage provider’s shared infrastructure, certificate-validation systems, other tenants or provider administrative services. Testing that requires authority from the storage provider must also comply with that provider’s authorization. Reports about Frameleaf’s backup integration are welcome even when the underlying storage is supplied by a third party.
Listing a hostname does not assert that its service is enabled for every customer or region, or that every aspect of a third-party system to which it points is within Frameleaf’s authority. If ownership or scope is uncertain, obtain clarification before testing it.
A customer’s Library hostname, custom domain, peer server, storage bucket or account is not included merely because it connects through Frameleaf. Use only accounts, servers and data you own or have express written permission to test. Our authorization does not replace the owner’s or hosting provider’s authorization.
4. Other products and excluded activity
Vulnerabilities in Frameleaf Library code may be reported through the same contact. Reproduce them on an installation you control and follow any applicable repository security policy. This Policy does not grant access to other people’s Library installations. Reports concerning Frameleaf applications, frameleaf.app or help.frameleaf.app are also welcome, but those systems are not included in this Cloud testing authorization without separate permission.
Do not perform:
- Denial-of-service, load, volume or destructive testing, or spam.
- Social engineering, phishing, physical attacks or attempts to obtain another person’s credentials.
- Credential stuffing, broad brute-force attacks, persistence, malware installation or movement into unrelated systems.
- Extraction, alteration, deletion or retention of another person’s data beyond the minimum unavoidable observation needed to recognize an issue.
- Testing of payment, email, hosting, storage or other third-party infrastructure without that provider’s authorization.
A scanner finding without demonstrated impact, a missing header alone or self-XSS may not establish an actionable vulnerability. You may still report a credible concern; do not escalate to harmful testing just to prove severity. Report suspected problems in Frameleaf’s integration with a provider to us, while directing vulnerabilities in the provider’s own service to that provider.
5. Research rules and accidental access
Use the least intrusive method needed, minimize requests and respect rate limits. Do not incur charges on another customer’s account or manipulate payments to obtain funds. Use test data and avoid interfering with availability, billing, backups or recovery access.
If you unexpectedly encounter another person’s information, stop the affected testing, do not browse further or download additional data, and report the event promptly. Retain only the minimum necessary non-sensitive description. Coordinate secure handling and deletion of any unavoidable evidence; do not redistribute it.
Testing that starts within scope must stop if continuing would violate these rules. Ask us before attempting a step that could affect customer data or service availability.
6. Safe harbour
For good-faith research conducted within this Policy and the authority Frameleaf can grant, Frameleaf considers the activity authorized and will not initiate or support legal action against you for that compliant activity under its terms or applicable anti-hacking laws. An accidental encounter with data does not by itself remove this protection if you promptly stop, minimize access and report it as required above.
If a third party questions compliant research, Frameleaf will explain that it was authorized under this Policy where lawful and appropriate. Frameleaf cannot bind an independent owner, provider, regulator or law-enforcement authority, waive another person’s rights or authorize access to systems outside its control. This protection does not cover extortion, deliberate data misuse or activity outside the stated scope.
7. Response and remediation targets
| Step | Target |
|---|---|
| Acknowledge a report | Within 3 business days of receipt |
| Initial triage and severity assessment | Within 7 calendar days of receipt |
| Critical vulnerability remediation or effective mitigation | Within 7 calendar days after confirmation |
| High-severity vulnerability remediation or effective mitigation | Within 30 calendar days after confirmation |
| Medium- or low-severity remediation | Within 90 calendar days after confirmation |
These are operational targets, not a promise that every report can be reproduced or permanently fixed within that period. We prioritize actual risk, exploitation, customer impact and available mitigations. Where a target cannot be met, we will explain the material limitation and provide an updated plan when doing so is safe and lawful. A mitigation can reduce immediate risk while a permanent fix is developed.
We will provide meaningful updates during remediation and coordinate attribution with you. Public credit is optional and does not require revealing your identity. There is no paid bounty programme under this Policy; submitting a report does not create a payment entitlement.
8. Coordinated disclosure
Please allow up to 90 calendar days from the report for investigation and remediation before publishing actionable technical details. Earlier disclosure may be agreed after a fix or mitigation is available. If more time is needed, we will explain why and seek a specific extension rather than treating the request as an indefinite prohibition.
Coordinate the timing and level of technical detail to reduce risk to customers who have not yet updated. Do not publish credentials, private content or information identifying affected customers without lawful authority. This process does not restrict legally protected reporting to regulators, law enforcement or advisers, or disclosure required by law.
9. Personal-data incidents
A vulnerability report is not automatically evidence of a personal-data breach. Frameleaf will assess credible incidents, contain harm, determine the affected information and provide notices required by applicable law and the Agreement.
For Customer Personal Data covered by the DPA, Frameleaf will notify the customer without undue delay and no later than 72 hours after becoming aware of a qualifying breach, unless a shorter mandatory deadline applies. Initial information may be supplemented as the investigation proceeds. Regulatory and individual notification duties have their own legal thresholds and deadlines; this is not a promise to wait 72 hours or to notify every authority and individual in every case.
Research response targets do not extend a statutory incident-notification deadline. Reports will be handled with access limited to the necessary investigation, remediation and legal purposes under the Privacy Notice and Security Schedule.
10. Contact and changes
Security contact: [email protected] or frameleaf.app.
Postal correspondence: Frameleaf, Inc., 14 Wall Street, Suite 2000, New York, NY 10005, United States. Telephone: +1 (332) 287-1911.
We may update the authorized scope and procedures prospectively. Changes do not retroactively withdraw the safe harbour for research that complied with the version in force when it occurred. A material new risk may require us to ask you to stop ongoing testing while we coordinate a safe approach.