Security - Fountain
Security at Fountain
At Fountain, we take security seriously. Please use the below form to disclose a security vulnerability.
Submission form
All fields are required unless marked optional.
Summary title
Help us get an idea of what this vulnerability is about.
Submission title
Target
Select the vulnerable target
Targets that are not explicitly in scope may not be eligible for acceptance.
Target
Select target…
- Worker Experience Platform - Employer
- Worker Experience Platform - Worker Portal
- Worker Experience Platform - API
- Fountain Applicant Experience Portal
- Fountain Applicant Experience Platform
- Fountain Applicant Experience API
- Other
Technical severity
The Vulnerability Rating Taxonomy is the baseline guide used for classifying technical severity.
VRT Category
Select or search for a vulnerability type
VRT Subcategory (optional)
VRT Variant (optional)
Vulnerability details
URL / Location of vulnerability (optional)
For example: https://secure.server.com/some/path/file.php
Description
Describe the vulnerability and its impact.
Provide a proof of concept or replication steps.
Maximum 25,000 characters.
Write in Markdown
Embed images by dragging & dropping, selecting, or pasting them. Markdown supported
Attachments (optional)
Attach proof-of-concept scripts, screenshots, screen recordings, etc.
You can attach up to 20 files. Please keep individual upload size under 400MiB.
You can embed attachments (.jpg/.gif/.png, smaller than 5MB) into the Markdown fields. You can copy the embed code using the ‘Copy as Markdown’ button.
By providing your email address you can claim your submission on bugcrowd.com.
Note: Submissions through this form are welcome. However, if you have been removed from the Bugcrowd platform or this customer’s engagements by the Platform Behavior Standards team:
- Your submission will still be reviewed.
- It cannot be claimed on the platform.
- You will not receive points, compensation, or accuracy increases for this work.
This form is intended solely for anonymous ethical disclosure and cannot be used to bypass removals.
Researcher email (optional)
Confirmation
Confirm your submission is accurate and adheres to Bugcrowd’s terms & conditions.
I agree to Bugcrowd’s terms & conditions as well as any additional rules and instructions provided by the organization hosting this program
Report vulnerability
Data encryption
Fountain forces HTTPS for all services using TLS (SSL). We also utilize HSTS to ensure that browsers only connect via secure HTTPS connections. Fountain uses AES-256 for encrypting documents at rest.
Fountain also regularly uses third-party security vendors to perform audits of our platform to ensure that we are using the best practices to keep all data secure.
Fountain Responsible Disclosure Policy
Data security is a top priority for Fountain, and Fountain believes that working with skilled security researchers can identify weaknesses in any technology.
If you believe you’ve found a security vulnerability in Fountain’s service, please notify us; we will work with you to resolve the issue promptly.
Disclosure policy
- Let us know as soon as possible when you’ve discovered a potential vulnerability by using the above submission form or emailing us at security@fountain.com. We vow to acknowledge your report as soon as possible. If you prefer to encrypt your communications, you can use our PGP key.
- Provide us a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within one week of disclosure.
- Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Fountain service. Please only interact with domains you own or for which you have explicit permission from the account holder.
Exclusions
While researching, we’d like you to refrain from:
- Denial of service
- Spamming
- Social engineering or phishing of Fountain employees or contractors
- Any attacks against Fountain’s physical property or data centers
Thank you for helping to keep Fountain and our users safe!
Changes to these guidelines
We may revise these guidelines from time to time. The most current version of the guidelines will be available at https://www.fountain.com/security.
Recognition
We would like to thank these individuals for their contributions.
- Muhammad Danish
- Maheshkumar Darji
- Ankit Thakur
- Swapnil Maurya
- Kunal Mhaske
- Gawasharks
- Harinder Singh(S1N6H)
- Avanish Dubey
Contact
Fountain is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to email us at security@fountain.com.
White Paper
Read our white paper – here