Vulnerability Disclosure Policy
How to report a security problem in Fire-Bid, what happens after you do, and the limits of testing that the operator treats as good faith.
Last updated 09/30/2026
What to Report
- A way to see or change another person's records, or another department's.
- A way to act as an administrator, or as the operator, without being one.
- A weakness in signing in, in password reset, or in how a session is kept.
- Personal information, credentials or secrets exposed where they should not be.
- Anything else that would let someone read, change or remove what they should not.
Where to Report
Email contact@fire-bid.com with "Security" in the subject line. Say which page or address is affected, the steps that show the problem, and what you were able to see or do. Include no more of anybody else's personal information than you need to show the problem exists. The same address is published for automated tools at /.well-known/security.txt.
What Happens Next
- Your report is acknowledged within 3 business days.
- You get an update within 14 days of reporting it, saying what was found and what is being done about it.
Testing in Good Faith
Testing is in good faith when it stays within these limits:
- Access no data beyond your own account. If you reach anybody else's records, stop there, keep no copy, and report it.
- No denial of service: nothing that floods, overloads or slows the service for other people.
- No social engineering: do not try to trick departments, their employees or the operator into giving anything up.
- Where you can, test against staging.fire-bid.com, which holds only fictional test data, rather than fire-bid.com.
No Legal Action for Good-Faith Research
Research carried out in good faith and within the limits above will not face legal action from the operator of Fire-Bid, James Bone. This commitment is the operator's own: it cannot speak for a fire department or for the hosting providers.
See the Security page for the protections in place.