Who is responsible
Benjamin Burns, founder of Fantail Forest, leads security for Isoplane and is accountable for the platform’s isolation design and for how reported vulnerabilities are handled. Fantail Forest, Ltd. is the New Zealand company that builds and operates Isoplane.
How to report a vulnerability
Email security@fantailforest.com or security@isoplane.dev. Tell us what you found, where you found it, the steps to reproduce it, and what an attacker could do with it. Please leave other people’s data out of the report.
The same contact details are published for scanners at /.well-known/security.txt.
What is in scope
- This website, isoplane.dev, and its subdomains.
- The Isoplane SDK packages and command-line tools we publish.
- The hosting platform, once the beta opens.
Each instance of an application runs in its own WebAssembly sandbox. A way out of that sandbox, or a way for one customer’s application to observe or affect another’s, is the kind of report we most want to receive.
What we ask of you
- Test only against accounts and applications that belong to you.
- Don’t read, change or delete data that isn’t yours. If you come across some, stop and tell us.
- Don’t degrade the service for other people: no denial-of-service testing, spam or social engineering.
- Give us a reasonable chance to fix the problem before you publish it.
What you can expect from us
We’ll confirm that we received your report, tell you what we found once we’ve investigated, and let you know when a fix ships. If you’d like credit for the finding, we’ll give it.