Vulnerability Disclosure Policy

We care about security. If you've found a vulnerability in Frugal, we want to hear about it. We welcome responsible disclosure and will work with you to understand and fix issues quickly.

Report a Vulnerability

Scope

In scope

Out of scope

If you're unsure whether something is in scope, just ask.

How to Report

Send your report to:

infosec@frugal.co

Helpful reports usually include:

Our Commitment

When you report a valid issue, we will:

Safe Harbor

If you follow these guidelines, we consider your research authorized:

If something goes wrong (it happens), stop and let us know right away.

Please Don't

Handling of Reports

All reports are logged and tracked through our vulnerability management process, prioritized based on risk and impact, and remediated according to our internal SLAs.

Disclosure

We follow a responsible disclosure approach: fix first, then disclose. We're happy to coordinate timing with you.

Recognition

We don't run a bug bounty, but we appreciate every solid report and are happy to offer public credit if you want it.

Questions?

Not sure if something is a vulnerability? Send it anyway or ask first. We'd rather see it than miss it.

infosec@frugal.co
Last updated: April 2026