FgFileGrab

FileGrab Security

Report security weaknesses and harmful content through the right channel so we can review them safely.

Report a vulnerability

Use the abuse and safety form, choose Security vulnerability, and include a concise description, affected URL or component, reproduction steps, expected impact, and any non-sensitive evidence. You can also emailabuse@filegrab.link.

Report harmful hosted content

Phishing, malware, fraud, impersonation, illegal content, child-safety concerns, privacy violations, and copyright reports belong in the abuse-report form. Include the exact FileGrab URL. Do not download or execute suspicious content to gather evidence.

Testing limits

Do not use security research as a reason to disrupt FileGrab or access data that is not yours. In particular, do not:

  • Access, alter, delete, or download another person's files, account, forms, or submissions
  • Run denial-of-service, load, spam, social-engineering, or physical-security tests
  • Upload malware, credential-harvesting pages, or illegal content
  • Test third-party providers, employees, customers, or infrastructure outside FileGrab's control
  • Publish sensitive details before FileGrab has had a reasonable opportunity to investigate and reduce risk

This page does not create a bug bounty, safe-harbor promise, or authorization to violate law, contracts, third-party rights, or the Terms of Service.

What happens after a report

Reports receive a reference ID when submitted through the form. FileGrab may request clarification, restrict access while reviewing a safety issue, preserve relevant evidence, and coordinate with service providers or authorities when appropriate. We do not promise a response or remediation deadline because severity, reproducibility, and legal obligations vary.

Work agent access

A work agent must confirm a valid email address before FileGrab displays its API key. Mailbox authorization lasts 7 days, and the agent must confirm access again after that period. Agent keys are limited to the approved link, upload, and file actions. They cannot manage billing, subscriptions, webhooks, or the admin interface.

File bytes upload directly to FileGrab storage through short-lived, signed instructions. The agent must send the exact file size and content type that FileGrab approved. FileGrab then checks the stored size and the public agent instructions require download verification before the agent reports success. Executable and installer filenames are not accepted through the current agent upload flow.

A standard FileGrab share URL can be opened by anyone who receives it until the link expires or the content is removed. Password-protected links also require the password. Share each link only with people who should receive the files. Read the work agent setup guide for the complete workflow.

Current protections and limits

FileGrab uses HTTPS, access controls, rate limiting, abuse reporting, content holds, and malware scanning for eligible executable files. Pro users can optionally enable browser-based file-content encryption on supported links. No security control or scanner can guarantee that every vulnerability or harmful file will be detected, so recipients should use normal caution with files from untrusted senders.