Template content awaiting legal review. Do not treat as binding.
Security policy
Last updated: 2026-05-22
RA-FEWS welcomes reports from security researchers. This page describes what is in scope, how to report a vulnerability, and the protections we extend to good-faith research.
Scope
This policy covers RA-FEWS production assets only: this website (currently served at rafews.tekhjem.no), the authenticated dashboard under /app, and the public RA-FEWS API it connects to (api.tekhjem.no/rafews). Staging and preview environments are out of scope.
In scope
The web application, the dashboard single-page app, and the FastAPI backend API are in scope. Examples of valuable reports: authentication bypass, broken access control, injection, server-side request forgery, and content-security-policy gaps.
Out of scope
Third-party integrations are out of scope: the DWD ICON-EPS data source, MapTiler and other basemap tile providers, Protomaps, Plausible Analytics, and hCaptcha. Report issues in those services to their respective vendors. Volumetric denial-of-service, social engineering, and physical attacks are also out of scope.
How to report
Email security@ra-fews.com with a clear description, reproduction steps, and the affected URL. If you need an encrypted channel for sensitive details, say so in your first email and we will arrange one. Do not disclose the issue publicly until we have confirmed a fix.
Disclosure timeline
We acknowledge reports within 3 business days, provide a triage assessment within 10 business days, and aim to remediate confirmed issues within 90 days. We will coordinate a public disclosure date with you once a fix has shipped.
Safe harbour
Good-faith security research conducted within this policy is authorised. We will not pursue legal action against researchers who avoid privacy violations, data destruction, and service degradation, and who give us reasonable time to remediate before any disclosure.
Security contact: security@ra-fews.com · /.well-known/security.txt