Security at FoundBefore
Implemented safeguards
- Platform-managed authentication and server-enforced roles.
- Tenant isolation and fail-closed account status checks.
- Private-by-default matching and consent-gated disclosure.
- Encryption for durable transactional email content.
- Rate limits, restrictive browser headers and append-only audits.
- Signed, replay-safe delivery webhooks and suppression controls.
Responsible reporting
Report a suspected vulnerability privately to office@foundbefore.com. Include the affected route, impact and safe reproduction steps. Do not access other participants' data, disrupt the service or publish details before a coordinated response.
Current scope
FoundBefore remains a controlled pilot. File exchange is not enabled without malware scanning and signed access. An independent penetration test, incident exercise and backup restore drill remain required before broad launch.