Fendhold · Legal
Security & Vulnerability Disclosure
Last updated: October 1, 2026
Keeping your plans and account safe matters to us. This page summarizes how we protect Fendhold and how security researchers can report a vulnerability. Our Privacy Policy explains what data we hold.
1. How We Protect Fendhold
- All connections to Fendhold use HTTPS (TLS).
- Passwords are stored only as salted hashes by our authentication provider.
- Each account can read and change only its own data, enforced on the server.
- Data is encrypted at rest by our hosting providers, and access by staff is limited to what is needed to run and support the service.
- The fendhold.com website loads no third-party scripts, trackers or fonts.
2. Reporting a Vulnerability
If you believe you have found a security vulnerability in Fendhold, email support@fendhold.com with the subject “Security report”. Please include a description of the issue, the steps to reproduce it, the affected URL or app version, and its potential impact. We will acknowledge your report within five business days, keep you informed of our progress, and tell you when it is fixed.
3. Good-Faith Research
When researching, please:
- test only against your own account, and do not access, change or delete other people’s data;
- stop and report as soon as you find a vulnerability, and access only the minimum data needed to demonstrate it;
- not perform denial-of-service testing, spam, social engineering, or physical attacks, and not use automated scanning that degrades the service;
- give us a reasonable time to fix the issue before disclosing it publicly.
If you follow these rules, we will consider your research authorized, will not pursue or support legal action against you for it, and will work with you to understand and fix the issue. We do not currently offer paid bug bounties.
4. Protecting Your Account
Use a strong, unique password, keep your device locked and up to date, and be wary of messages asking for your password; we will never ask for it. If you think your account has been compromised, change your password and email support@fendhold.com.