Last updated: July 14, 2026
ForthWrite takes the security of our service and the data our users entrust to us very seriously. We welcome reports of security vulnerabilities from the security research community and operate a coordinated disclosure program.
Email curtis@forthwrite.ai with the subject line Security report - [brief summary].
Please do not file a public GitHub issue, post on social media, or otherwise disclose the issue publicly until we have had a reasonable opportunity to investigate and remediate.
To help us triage your report quickly, please include where possible:
Security research conducted under this policy is considered:
We will not pursue legal action against, or take retaliatory action toward, researchers who report vulnerabilities in good faith following this policy and avoid privacy violations, destruction of data, degradation of our service, social engineering, or testing on accounts that do not belong to them.
In scope:
forthwrite.ai/api/*gmail.readonly, gmail.compose, userinfo.email) and Microsoft (Mail.Read)commands, chat:write, channels:history, groups:history, im:history, mpim:history; user scopes channels:read, groups:read, im:read, mpim:read, users:read, users:read.email, and usergroups:readOut of scope:
ForthWrite has passed CASA Tier 2 assessment as required by Google for applications using the restricted gmail.readonly scope. Hardening implemented as part of the assessment:
npm audit (zero vulnerabilities)sendDefaultPii: false, session-replay masking, and a defense-in-depth scrubber that redacts emails, bearer tokens, and JWTs before transmissionexternally_connectable to forthwrite.ai only (no Vercel preview URLs, no localhost in shipped builds)This policy is also published in machine-readable form at /.well-known/security.txt per RFC 9116.