Use email for account support or sensitive security reports. Use the public issue channel for reproducible, non-sensitive product and accessibility feedback.
01
What to include
State the page route, what you entered or expected at a non-sensitive level, what happened, and the browser/device context if it affects display or accessibility. Do not include passwords, API keys, full tokens, financial account information, or personal data.
For a formula or source correction, identify the formula term, source claim, date, and a public supporting reference where available. This makes corrections reviewable without collecting more information than needed.
02
Security reports
Do not test private targets, cloud metadata endpoints, credentials, or someone else’s systems through UtilityForge. Report a suspected security weakness with the route, a non-destructive description, and evidence that does not expose a secret.
Email security@utilityforge.app for private vulnerability reports. Please include a concise impact summary and safe reproducer; do not attach secrets or personal data. We aim to acknowledge reports within five business days. Use support@utilityforge.app for account and billing help, and https://utilityforge-v2-site.vercel.app/account for password recovery and session revocation, which are self-service now.
The machine-readable version of this process is published at /.well-known/security.txt, with the scope, testing rules, and the payment and playground surfaces that are explicitly in scope.
03
Response practice
UtilityForge records meaningful product and policy changes in the public changelog. The project does not promise a particular response time, outcome, feature delivery date, or financial/product recommendation.
This contact process was last reviewed on 27 August 2026.