Responsible Disclosure - Figment

Responsible Disclosure

Figment welcomes reports from third party security researchers and their help in making our services and platforms more secure.

Bug Bounties

Figment believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We currently have a vulnerability disclosure program in place on BugCrowd, you can find more details here.

Rules of Engagement

Figment will not pursue legal action against you as long as you submit your findings in accordance with the above rules. Figment reserves all legal rights in the event of noncompliance with these rules.

Data exfiltration, continued exploitation, and public disclosure prior to Figment review shall be considered malicious, unauthorized activity, and, in such instances, Figment will pursue legal action against you, including reporting such activity to law enforcement agencies.

Note: Please allow us 10-14 days to investigate vulnerability disclosure reports. In addition, please note that payments to security researchers can only be made by Venmo or PayPal at this time.

By submitting a report, you are indicating that you have read, understand, and agree to the above requirements.

Thank you,

Figment Security.