Security at Forzelite
We train minors and collegiate athletes — their data deserves rigor. If you've found a security issue, we want to hear from you.
Report a Vulnerability
Email security@forzelite.com with a description of the issue, steps to reproduce, and any supporting material. If your report contains sensitive details, ask us for our PGP key at the same address before sending.
Our Commitment (Response SLA)
- Acknowledgment of your report within 48 hours.
- Triage and severity assessment within 7 days.
- Fix timeline communicated after triage; critical issues are targeted for remediation within 90 days.
- Coordinated disclosure once a fix is deployed — with credit to you, if you'd like it.
Safe Harbor
Good-faith security research is protected here. If you comply with this policy — no data destruction, no privacy violations, no service disruption, no exploitation beyond what's needed to demonstrate the issue — we will not pursue legal action against you for your research, and we'll work with you to understand and resolve the issue quickly.
Scope
In scope:
- forzelite.com and its subdomains (app, api, developers)
- The Forzelite iOS and Android applications
- The Forzelite Partner API (/api/v2/external/*)
Out of scope:
- Denial-of-service testing and automated scanning that degrades service
- Social engineering of Forzelite staff, coaches, or athletes
- Third-party services and vendors not operated by Forzelite
- Issues requiring physical access to a user's device
Hall of Fame
We publicly thank researchers who report valid issues (with their permission). No entries yet — yours could be the first.