Reporting a security problem
In short
Email security reports to us with enough detail to reproduce the issue. Please do not access other people's data while testing.
How to report
Send the report through the contact page and mark it as a security issue. Include what you found, the steps to reproduce it, and what an attacker could achieve with it.
Reproduction steps matter more than severity claims. A report that can be reproduced gets fixed; one that cannot be usually stalls in clarification.
What we ask of researchers
Test against your own account. Do not access, modify or store other people's data, and do not run tests that degrade the service for other users.
If you do incidentally encounter someone else's data, stop, and say so in the report. That is treated as good-faith disclosure rather than a problem.
Give us a reasonable window to fix an issue before publishing it.
What happens next
Reports are acknowledged, reproduced, and fixed in order of real-world impact rather than reported severity.
Frenzsave is operated by a small team. We would rather tell you that plainly than advertise response targets we cannot consistently meet — an unmet commitment is worse than an honest one.
