If you discover a security vulnerability in Fournex, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Email: security@fournex.com
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes
We will respond within 72 hours and aim to release a fix within 14 days for confirmed issues.
This policy covers the open-source Fournex CLI and SDK (pip install fournex).
- Vulnerabilities in third-party dependencies (report to the upstream project)
- Issues requiring physical access to the machine
- Social engineering attacks