Legal
Policy

CAID TECHNOLOGIES, INC.

Security and Vulnerability Disclosure Policy

How to report vulnerabilities safely.

Last updated July 8, 2026Effective July 8, 2026

Reporting

Send vulnerability reports to team@caid-technologies.com. Include affected URLs, API routes, packages, reproduction steps, impact, evidence, and whether any data that was not yours was accessed.

In Scope

  • The public Forma web application.
  • Documented Forma APIs.
  • Authentication, authorization, project access, and integration handling.
  • Public repository code maintained by Forma.

Out of Scope

  • Denial-of-service or load testing.
  • Social engineering, phishing, or physical attacks.
  • Attacks against third-party providers or suppliers.
  • Accessing, modifying, deleting, or exfiltrating data that is not yours.
  • Automated scanning that degrades the Service.

Safe Harbor

If you act in good faith, follow this policy, avoid privacy violations and disruption, and report issues promptly, Forma will not pursue legal action against you for the research itself.