March 13, 2026
At Fynd, we deeply appreciate the efforts of ethical hackers and security researchers who act in good faith to help us improve our platform’s security. We understand that finding bugs and vulnerabilities takes time and skill - and we welcome responsible disclosure that protects our systems, users, and data.

At Fynd, we deeply appreciate the efforts of ethical hackers and security researchers who act in good faith to help us improve our platform’s security. We understand that finding bugs and vulnerabilities takes time and skill - and we welcome responsible disclosure that protects our systems, users, and data.
That said, we’ve seen a growing number of messages from individuals who report bugs and immediately request money to fix them. This post is to clarify our standard process and explain what to expect when you discover a vulnerability on our platform.
We officially support good-faith security research under a publicly available Vulnerability Disclosure Policy. This policy is designed to:
You can find the full document here, or contact us at security@fynd.com.
We allow non-destructive testing of our publicly accessible systems, specifically:
Always follow responsible testing guidelines. Any activity outside the defined scope may void protection and be treated as unauthorized.
To responsibly report a vulnerability, email security@fynd.com with the following:
We aim to acknowledge valid reports within 5 business days and will work with you through the investigation and resolution process.
We follow a 90-day embargo policy:
Researchers are expected not to publicly disclose any details for 90 days after acknowledgment so we can remediate the issue and protect users.
If a critical issue is actively being exploited or requires faster action, we may accelerate coordinated disclosure. Unauthorized public disclosure may void safe harbor protections.
If your report is valid and valuable, we may offer:
❗ However, we do not offer cash rewards, bounties, or payments unless previously agreed to in writing. We do not participate in any bug bounty program at this time.
We strictly prohibit:
Researchers who violate these rules will lose safe harbor protection, and we may involve legal teams as needed.
If you’ve found a bug, thank you! Here’s what to do:
Let’s build a safer web - together.
Wondering if AI skin analysis works for darker skin tones too? Here's how the tech reads every skin type, where it slips up, and what to check before you pick a tool.
Learn what it takes to build a company AI agent through Fynd’s journey with Raju, from tools and memory to context, orchestration and the Company Brain.
See how virtual try-on works, which retail categories benefit most and how to implement it, measure ROI and choose the right platform for your store.
Fill out the form
Share your contact information to get started
Speak to an expert
A member of our sales team will get in touch with you