Security
Responsible disclosure
We take the security of our users and their data seriously. If you have discovered a vulnerability in FanStudio, please tell us — we want to fix it.
How to report
Email support@fanstudio.ai with SECURITY in the subject line and a clear description of the issue. Please include:
- A short summary of the vulnerability.
- Steps to reproduce (or a proof-of-concept).
- The impact you believe it has.
- Your name or handle if you would like credit.
If the report contains sensitive details, you may encrypt it; contact us first and we will share a PGP key.
Our response commitment
- Acknowledgement: within 3 business days.
- Triage and initial assessment: within 7 business days.
- Status updates: at least weekly until the issue is closed.
- Resolution target: critical issues within 7 days, high within 30, medium and below within 90 — whenever a fix is technically feasible.
Scope
The following are in scope for reporting:
- The FanStudio web application and dashboard.
- The FanStudio API (api.fanstudio.ai).
- OAuth integrations FanStudio operates (including Fanvue).
- Authentication and session handling, payment flows, user-data access controls.
Out of scope:
- Vulnerabilities in third-party services FanStudio depends on (Clerk, Stripe, AWS, AI model and inference providers, Fanvue). Please report those directly to the vendor.
- Findings that require physical access to a user's device.
- Volumetric DDoS or other availability-only attacks.
- Reports based on outdated or unsupported software versions.
- Social engineering of FanStudio staff or users.
Safe-harbour
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, destruction of data, and degradation of service.
- Only interact with accounts they own or with explicit permission from the account owner.
- Stop testing and notify us promptly when they encounter other users' data.
- Do not exploit the issue beyond what is necessary to demonstrate it.
- Give us a reasonable window to remediate before public disclosure (we suggest 90 days).
Recognition
We do not currently run a paid bug-bounty programme. We credit responsible reporters by name on this page once a fix has shipped, with their permission.
Non-security issues
If your issue is not a vulnerability — billing, account access, a bug in the app — email support@fanstudio.ai without the SECURITY subject tag. Reports marked SECURITY are triaged with priority and handled exclusively as vulnerability reports.