Security Policy

Reporting Security Issues

The Making Fantasies Real team takes security seriously. If you believe you've found a security vulnerability in our website or services, please report it to us as described below.

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, please send an email to [email protected].

What to Include

To help us better understand and address the issue, please include:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit the issue

Response Policy

When you report a vulnerability, our security team will:

  • Acknowledge receipt of your vulnerability report within 48 hours
  • Provide an estimated timeline for a fix
  • Notify you when the vulnerability is fixed
  • Recognize your contribution (if desired) after the vulnerability is fixed