Fellowrise · Protecting access
Security and responsible reporting
Draft prepared September 6, 2026
Access checks protect community data, but private does not mean end-to-end encrypted. Share sensitive information carefully.
On this page
1.Account and community access
Public member access uses email sign-in links. Sign-in links are short-lived and single-use, and their stored tokens are hashed. Active membership and permissions are checked before protected community actions.
File downloads require authorized community access. Private-message queries require conversation participation; community staff do not receive a general private-message viewer.
2.Files and request safeguards
The app validates supported upload formats, sizes, and image dimensions. It applies restricted file-response headers and private caching rules. This is not a claim that every uploaded file is malware-scanned.
Mutation routes use origin checks, and sign-in requests have rate limits. These safeguards are part of the implementation, not a certification or guarantee that incidents cannot happen.
3.Understand the limits
Private messages and community content are stored by the service and are not end-to-end encrypted. Do not share passwords, secret keys, financial account credentials, or highly sensitive documents.
Fellowrise does not make a SOC 2, ISO certification, fixed incident-response time, or zero-risk promise on this page. Access to a private community cannot prevent another participant from taking a screenshot.
4.Report a suspected security problem
Contact the Fellowrise team with the affected page, a brief description, the approximate time, and safe steps to reproduce the issue. Do not include live sign-in links, access tokens, passwords, or other members’ private content.
Do not access, alter, download, or expose data belonging to other people while investigating. Stop if you encounter sensitive information. This page does not authorize intrusive testing, create a bounty program, or grant a legal safe harbor.