Security
Security Policy
Revision date: 2026-06-28. This document applies together with the Terms of Service and Privacy Policy.
1. Reporting
Report vulnerabilities to ft.futuretechcorp@gmail.com, fta4dmin2@yandex.ru. The public researcher file should be available at https://futuretechcorp.org/.well-known/security.txt after domain publication.
2. Accepted reports
Accepted topics include broken access control, IDOR/BOLA, XSS, SSRF, SQL injection, RCE, secrets exposure, unsafe authorization, MFA bypass, unsafe token storage, unsafe artifact processing, API vulnerabilities, infrastructure misconfiguration and insecure Drasl/OIDC integration.
3. Safe testing boundaries
Use your own account, do not access third-party data beyond minimal proof, do not disrupt availability, do not change other users' content, do not publish before response and do not use malware against real users.