Security

Responsible disclosure

We take the security of our users and their data seriously. If you have discovered a vulnerability in FanStudio, please tell us — we want to fix it.

How to report

Email support@fanstudio.ai with SECURITY in the subject line and a clear description of the issue. Please include:

  • A short summary of the vulnerability.
  • Steps to reproduce (or a proof-of-concept).
  • The impact you believe it has.
  • Your name or handle if you would like credit.

If the report contains sensitive details, you may encrypt it; contact us first and we will share a PGP key.

Our response commitment

  • Acknowledgement: within 3 business days.
  • Triage and initial assessment: within 7 business days.
  • Status updates: at least weekly until the issue is closed.
  • Resolution target: critical issues within 7 days, high within 30, medium and below within 90 — whenever a fix is technically feasible.

Scope

The following are in scope for reporting:

  • The FanStudio web application and dashboard.
  • The FanStudio API (api.fanstudio.ai).
  • OAuth integrations FanStudio operates (including Fanvue).
  • Authentication and session handling, payment flows, user-data access controls.

Out of scope:

  • Vulnerabilities in third-party services FanStudio depends on (Clerk, Stripe, AWS, AI model and inference providers, Fanvue). Please report those directly to the vendor.
  • Findings that require physical access to a user's device.
  • Volumetric DDoS or other availability-only attacks.
  • Reports based on outdated or unsupported software versions.
  • Social engineering of FanStudio staff or users.

Safe-harbour

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, destruction of data, and degradation of service.
  • Only interact with accounts they own or with explicit permission from the account owner.
  • Stop testing and notify us promptly when they encounter other users' data.
  • Do not exploit the issue beyond what is necessary to demonstrate it.
  • Give us a reasonable window to remediate before public disclosure (we suggest 90 days).

Recognition

We do not currently run a paid bug-bounty programme. We credit responsible reporters by name on this page once a fix has shipped, with their permission.

Non-security issues

If your issue is not a vulnerability — billing, account access, a bug in the app — email support@fanstudio.ai without the SECURITY subject tag. Reports marked SECURITY are triaged with priority and handled exclusively as vulnerability reports.