Report a vulnerability
Use the abuse and safety form, choose Security vulnerability, and include a concise description, affected URL or component, reproduction steps, expected impact, and any non-sensitive evidence. You can also email abuse@filegrab.link.
Report harmful hosted content
Phishing, malware, fraud, impersonation, illegal content, child-safety concerns, privacy violations, and copyright reports belong in the abuse-report form. Include the exact FileGrab URL. Do not download or execute suspicious content to gather evidence.
Testing limits
Do not use security research as a reason to disrupt FileGrab or access data that is not yours. In particular, do not:
- Access, alter, delete, or download another person's files, account, forms, or submissions
- Run denial-of-service, load, spam, social-engineering, or physical-security tests
- Upload malware, credential-harvesting pages, or illegal content
- Test third-party providers, employees, customers, or infrastructure outside FileGrab's control
- Publish sensitive details before FileGrab has had a reasonable opportunity to investigate and reduce risk
This page does not create a bug bounty, safe-harbor promise, or authorization to violate law, contracts, third-party rights, or the Terms of Service.
What happens after a report
Reports receive a reference ID when submitted through the form. FileGrab may request clarification, restrict access while reviewing a safety issue, preserve relevant evidence, and coordinate with service providers or authorities when appropriate. We do not promise a response or remediation deadline because severity, reproducibility, and legal obligations vary.
Current protections and limits
FileGrab uses HTTPS, access controls, rate limiting, abuse reporting, content holds, and malware scanning for eligible executable files. Pro users can optionally enable browser-based file-content encryption on supported links. No security control or scanner can guarantee that every vulnerability or harmful file will be detected, so recipients should use normal caution with files from untrusted senders.