FeFe women's research panel logoBack to FeFe

Security and vulnerability disclosure

This page is maintained by FeFe. It describes the controls we operate and how to tell us about a security problem.

Last updated 4 August 2026

How we protect the platform

  • Row level access rules so each account can reach only its own data.
  • Balances and payments can only be changed by validated server side processes.
  • Traffic is encrypted in transit, and card details are handled by Stripe, never by us.
  • Administrative access is limited to what is needed to operate the service.
  • Sensitive actions in the admin console are recorded in an audit log.

These are the controls we operate today. They are not a certification, and no service can promise it will never be breached.

Reporting a vulnerability

Email marianatmatthews@gmail.com with "Security" in the subject line. Include the steps to reproduce, the impact, and anything we need to see it ourselves. We aim to acknowledge within 3 working days and to keep you updated until it is resolved.

Please do

  • Use your own test account and your own data.
  • Stop as soon as you have confirmed a problem exists.
  • Give us reasonable time to fix it before telling anyone else.

Please do not

  • Access, download, modify or delete another person's data.
  • Run denial of service, spam or high volume automated scans.
  • Use social engineering against our users or providers.
  • Publish details of an unfixed issue.

Safe harbour

If you follow this policy in good faith, we will treat your research as authorised, will not pursue legal action against you for it, and will work with you on a fix. FeFe does not currently run a paid bug bounty, but we are glad to credit you.

Data breaches

If a personal data breach affects you, we will tell affected users and, where required, the Information Commissioner's Office within 72 hours of becoming aware. Researcher notification duties are in our data processing terms.