Reporting a vulnerability
If you have found a security vulnerability in frameFUSION, please report it to security@lemyframe.com.
Please do not disclose it publicly until we have fixed it and agreed on coordinated disclosure.
A useful report includes:
- a description of the issue and why you consider it a security problem,
- the frameFUSION version (see “About”) and operating system,
- reproduction steps or a proof of concept,
- your assessment of the impact and, if you have one, a suggested mitigation.
What to expect
We will keep you informed of progress. Security updates are provided free of charge and regardless of licence status.
| Step | Target |
|---|
| Acknowledgement of receipt | 72 hours |
|---|
| Initial assessment | 10 business days |
|---|
| Remediation plan with target date | 30 days from acknowledgement |
|---|
| Notification that a fix has shipped | with the release containing the fix |
|---|
Coordinated disclosure
We publish vulnerability details after a fix is available to users, normally within 90 days of acknowledgement. If a fix needs longer, we will agree an extension with you.
We credit reporters by name with their consent, and respect requests to remain anonymous. We do not operate a paid bug bounty programme.
Safe harbour
then we will not pursue legal action against you and we consider your research authorised.
If you research the security of frameFUSION in good faith and you:
- do not access, download, modify or delete other people's data,
- do not degrade availability or run denial-of-service attacks,
- do not use social engineering, phishing or physical access,
- test only your own installation or one you have the owner's explicit permission to test,
- report your finding to us allowing reasonable time before disclosure,
Scope
In scope: the frameFUSION desktop application (Electron), the local API server shipped with it, the update mechanism (updates.lemyframe.com) and the licensing service.
Out of scope: third-party infrastructure (Neon, Cloudflare, Microsoft), customer-modified installations, and findings without demonstrable security impact.
Supported versions
Security updates are issued for the latest released version. The support period is 5 years from the date of the most recent release.
This policy fulfils Annex I Part II §§5–6 of Regulation (EU) 2024/2847 (Cyber Resilience Act).