- Users must protect credentials, devices, sessions, recovery channels, and officer accounts, and must report suspected compromise promptly.
- Researchers may report vulnerabilities through the published security contact. Testing must be authorized, proportionate, and must not access, change, exfiltrate, disrupt, or disclose user, group, payment, claim, or audit data.
- FelbaCare may investigate suspicious access, preserve logs, revoke sessions, rotate secrets, notify affected users, and report unlawful activity where appropriate.
- Security descriptions are transparent safeguards, not a guarantee that the service is immune from all risk.
Security and Responsible Disclosure Policy
Security expectations, protected testing, vulnerability reports, and prohibited exploitation.