Security at Filen
At Filen, we care deeply about the safety and security of our customer's data. This is why we greatly value any inputs from our community that can help us detect vulnerabilities in our product.
How to report an issue
If you have discovered an issue that is not part of our out-of-scope vulnerabilities, please create a ticket at
https://filen.io/contact with the following details:
1. A summary of the issue and potential impact
2. A breakdown of the steps to replicate the issue
3. Details of the environment you are using
4. If available, any proof-of-concept code to exploit the vulnerability
Upon receiving your ticket, our team will start investigating the issue. We will keep you updated on the progress and may reach back for further details if needed.
Of course, we want to compensate your effort, so for any valid vulnerabilities we will reach back to you with a financial reward.
Focus areas
1. Authentication bypass and privilege escalation
2. Exposure of personally identifiable information (PII)
3. Access to data outside of the authenticated drive
4. SQL injection and remote command execution
5. Access to deeper parts of our infrastructure
In scope
8. Our mobile app
9. Our desktop client
10. Our CLI
Out of scope
1. Automated scanning of any kind
2. Social engineering of any kind, in particular Filen employees
3. Denial of Service attacks of any kind
4. Attacks requiring physical access to the victim's computer or our datacenters
5. Theoretical attacks without proof of exploitability
6. Man-in-the-middle attacks
7. Clickjacking on pages with no sensitive actions
8. High-privilege users (admins, owners) using a bug to sabotage/deface their own drive
9. Logic bugs which allow an attacker to bypass limits on free accounts and get access to features on paid plans
10. Missing best practices in CSP, email, DNS records or cookies may be considered informative but are unlikely to qualify for any reward
We kindly ask you
1. Only test the vulnerability on your own account or with explicit permission from the account holder
2. Make a good faith effort to avoid privacy violations, copying or destruction of data, and interruption or degradation of our service
3. If you obtain remote access to our systems, do not attempt to expand or elevate access to other servers
4. To prevent further exploitation, please do not make the vulnerability public before reporting it to us, and give us adequate time to address the issue
Safe harbor
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.