Vulnerability Disclosure Policy
If you found a security problem in this website, we want to hear about it. We handle reports ourselves and there is no bounty program.
Last updated Aug. 14, 2026
Reporting a problem
Email spencer.wood@foundationconsultantgroup.com with enough detail that we can reproduce what you found. The same address is published in our security.txt.
Useful reports include the URL or request involved, the steps you took, what you expected, what happened instead and any proof-of-concept you are willing to share. Screenshots help. Tell us how you would like to be credited, or say you would rather not be.
What we will do
- Acknowledge your report within five business days.
- Tell you whether we consider it in scope and whether we can reproduce it.
- Keep you updated while we work on it, and tell you when it is closed.
We are a small firm and we are not going to promise a fix by a certain date. We will tell you where it stands whenever you ask.
What is in scope
- foundationconsultantgroup.com and its subdomains
- The contact form and the code behind it
- The HTTP response headers, redirects and content security policy this site serves
What is out of scope
- Our clients' systems. If you found something in a government network we happen to advise, report it to that organization, not to us. We cannot authorize testing of somebody else's systems.
- Services we buy. Issues in Cloudflare, Resend or Google Fonts belong to those companies and have their own disclosure programs.
- Social engineering of Spencer Wood, subcontractors or anyone else associated with the firm, including phishing and pretext calls.
- Physical attempts against property, offices or people.
- Denial of service, load testing or anything that degrades the site for other people.
- Scanner output with no working attack behind it, and best-practice suggestions like a missing header that leads nowhere. Tell us anyway if you like, and expect a lower priority.
Testing rules
Stay within the scope above. If you reach data that is not yours, stop, and do not download, save, alter or pass on any of it. Do not degrade the service for other visitors, and use test data instead of a real person's information. Give us a reasonable chance to fix the issue before you publish anything about it, and talk to us about timing if you plan to write it up.
Safe harbor
If you follow this policy in good faith, we will treat your work as authorized research. We will not pursue legal action against you, and we will not ask your internet provider or employer to act against you. If a third party brings a claim about research you did while following this policy, we will say publicly that your work was authorized.
If you are unsure whether something is in bounds, ask before you test.
We do not pay bounties
There is no reward program here and no payment for reports. We will credit you by name on request once an issue is fixed.
Changes to this policy
The version in force is the one that was posted when you started testing.