Include
Send a short description of the issue, the affected Focusward version, Chrome version, operating system, reproduction steps, expected behavior, actual behavior, and any evidence that helps explain impact. Redact private browsing history, personal identifiers, payment details, license keys, and credentials.
If the report involves the license service, include the endpoint and a request identifier if one was shown. Never include a CREEM API key or webhook secret.
Avoid
Do not test against another person's account, attempt to obtain or expose another user's data, disrupt the production service, or send destructive payloads. Use a local test profile when possible. Do not send a complete payment card number, password, or complete license key.
Response
We will acknowledge a report when practical and may ask for clarification. We will assess severity, work on a fix or mitigation, and communicate when the issue is resolved or when more time is required. There is no paid bug bounty program.
Product scope
Focusward is a Chrome extension and a small license service. Goals, domain lists, session history, and focus enforcement data remain in Chrome local storage. The extension cannot control other browsers, other profiles, other devices, Chrome system pages, or a user who disables or removes the extension.
Send reports to sohaibk1001@gmail.com. Use the subject line Focusward security report.