Security Policy
Effective July 16, 2026
Reporting a vulnerability
If you believe you've found a security issue in the Semfora cloud service or this website, email contact@semfora.ai. Include enough detail to reproduce the issue: affected component, steps, and impact as you understand it. This policy is also published in machine-readable form at /.well-known/security.txt.
Please don't discuss suspected vulnerabilities in public channels until we've had a chance to fix them.
What to expect
We'll acknowledge your report within 3 business days and keep you updated as we investigate. Once a fix ships, we're glad to credit you in the release notes unless you'd rather stay anonymous.
Scope
In scope: the Semfora cloud platform (analysis pipeline, dashboard, PR gate, chat, integrations, AI features) and this website, including the signup and webhook endpoints.
Out of scope: social engineering, denial of service, and vulnerabilities in third-party dependencies already publicly known (though heads-up reports are welcome).
Safe harbor
We won't pursue legal action for good-faith security research that stays within scope, avoids privacy violations and data destruction, and gives us reasonable time to remediate before disclosure.
How we handle your source
Analysis runs in single-use, ephemeral containers: your repository is checked out, measured, and the workspace is deleted when the run ends. Stored results are limited to names and numbers: the metrics schema has no field that can carry source text, and callbacks are HMAC-signed and size-capped.
Reports about the accuracy of scan results (false positives or missed patterns) are welcome at the same address; they're not vulnerabilities, but we treat signal quality as seriously as security.
If something goes wrong
If we learn of a breach affecting customer data, we notify affected customers without undue delay, consistent with applicable law, with what happened, what data was involved, and what we're doing about it. Details on data handling are in our privacy policy.