Security Disclosure Policy

Effective: April 1, 2026 · Format Dynamics, Inc. (DBA BlueFox)

1. How to Report

If you believe you have found a security issue in BlueFox Edge (the API, the website, or a published SDK), email support@bluefoxedge.ai. Use the subject line 'Security report' so it is triaged ahead of general support.

2. What to Include

The affected endpoint or page, the steps to reproduce, and what you observed. If the issue involves a signed receipt, include the receipt bytes you checked. Please do not include another person's data in a report.

3. What to Expect

We acknowledge reports on a best-effort basis and prioritize fixes by severity. We do not currently operate a paid bounty program. Please give us a reasonable window to remediate before public disclosure — coordinate timing via support@bluefoxedge.ai.

4. Scope Notes

Testing must not degrade the service for others: no denial-of-service, no volumetric testing against production, and no access to data that is not yours. The machine-readable contact record is published at /.well-known/security.txt (RFC 9116).

← Back to BlueFox Edge