We take security and compliance seriously, and it is hardwired into all our processes so you can focus on building something awesome.
Working with FusionAuth means integrating an enterprise-ready solution that considers security, privacy, and compliance our crucial responsibility and a top priority in everything we build.
Building an authentication system can be time and cost-intensive for system engineers. Traditionally, organizations have maintained servers dedicated to authentication. Nowadays, third-party authentication providers like FusionAuth help minimize internal maintenance costs and improve security by keeping up with modern best practices for their users.
Learn moreThereās no industry, no organization, and no software that is immune to the antics of hackers. Personal information, corporate data, and even high-profile social media accounts are under constant attack. Any server system accessible from the Internet is an actual target. Learn how to get ahead of, it in our detailed guide below.
Learn moreFusionAuth can be deployed on any server, anywhere in the world. This makes it simple for companies to ensure FusionAuth complies with GDPR. And we are happy to sign BAA for companies that wish to leverage FusionAuth Cloud and need to comply with healthcare industry regulations.
If you've discovered a bug in our website, our account systems, or the FusionAuth application itself, review all of the information below to learn about our responsible disclosure process and guidelines. Once you've read through everything, please submit your report via the form below.
If you have discovered or believe you have discovered a potential security vulnerability, we encourage you to disclose it in accordance with this responsible disclosure program.
We will work with you to validate and respond to security vulnerabilities that you report to us. Because public disclosure of a security vulnerability could put the entire FusionAuth community at risk, we require that you keep such potential vulnerabilities confidential until we are able to address them. We will not take legal action against you or suspend or terminate your access to any FusionAuth services, provided that you discover and report security vulnerabilities in accordance with this Responsible Disclosure Program. FusionAuth reserves all of its legal rights in the event of any noncompliance.
Please read this carefully to ensure you understand both the allowed and disallowed methods for discovery. FusionAuth reserves all of its legal rights in the event of any noncompliance.
We encourage responsible security research on the FusionAuth website - fusionauth.io, and all sub-domains, FusionAuth Cloud services, and other FusionAuth web services and standalone software libraries. We allow you to conduct vulnerability research and testing on the FusionAuth Cloud services to which you have authorized access. Authorized access includes FusionAuth Cloud services that you have purchased, FusionAuth Cloud account management for your account, or company owned account.
In no event shall your research and testing involve:
Please take the time to read and understand each of the above points. In the event that you do not have adequate clarity on the method of your discovery, please inquire before proceeding to ensure compliance.
We encourage anyone that believes they have found a security vulnerability in our website, FusionAuth Cloud, FusionAuth, or other FusionAuth web services, to responsibly disclose the issue.
If you can get FusionAuth to do something it isn't supposed to do that causes it to lose data integrity, availability, leak information, or provide unauthorized access to APIs or data - you found a vulnerability and we want to know about it - right now! š§
We want to reward you for your efforts in helping us continue to enhance product security. We do this by paying out bounties for security vulnerabilities to the first person to complete a verifiable disclosure. Please review and follow these simple rules before you submit your disclosure.
Please do these things, it will serve us both.
Please don't do any of these things, it won't help either of us.
It may take us from 1-2 weeks to review the report and verify the vulnerability. If your report not does not meet the submission guidelines, or does not adequately prove a vulnerability the report will be rejected.
In most cases, when a report is rejected, the FusionAuth security team will respond to ask for additional clarification or evidence. However, if it is clear that the reporter has not invested any reasonable amount of time to follow the submission guidelines, no response will be offered. We value your time and effort, we ask that you do the same for us.
Once we determine a report has identified a real vulnerability you can expect that we will let you know we have accepted your report. If we are able to offer you a bounty, we will communicate the amount, and ask you for preferred payment method. Please note that does not guarantee we can use your preferred method, but we will do our best.
If we can improve this submission guide, provide additional clarification, examples etc., please contact us.
FusionAuth is a complete solution with no sacrifices. We got this. Go build something awesome.
start for free