Legal
Security disclosure policy
How to report a Flowpane vulnerability safely, with optional researcher credit and no monetary rewards.
Updated: 2 October 2026
Report a vulnerability
Report suspected vulnerabilities through the security reporting form or security@flowpane.com. Include the affected address or component, a concise description and impact, minimal non-destructive reproduction steps, and a safe proof of concept if needed. Remove secrets and other people's personal data. Ask us for a suitable transfer method before sending sensitive supporting evidence.
If you provide contact details, we can ask questions and update you. You may report by email without identifying yourself, but we cannot reply without a reachable address. Do not send reports through public issue trackers or social media.
Scope and safe research
This reporting policy covers suspected vulnerabilities in Flowpane-operated websites, the application, documentation and Flowpane-supplied software. It does not authorise testing client websites, third-party services or infrastructure merely because they integrate with Flowpane or share its hosting.
Use only accounts, data and systems you own or have explicit authority to test. A reporting policy is not blanket permission to probe every Flowpane hostname or an exemption from the law. If the scope or safety of a test is uncertain, ask before proceeding.
- Do not access, copy, change or delete another person's data, exploit a finding beyond the minimum proof, establish persistence, or move into another system.
- Do not perform denial-of-service tests, disruptive scanning, brute-force attacks, spam, phishing, social engineering or physical intrusion.
- If you encounter personal data, credentials or unintended access, stop testing immediately and report what happened without collecting further evidence. Do not retain or disclose that material unnecessarily.
Handling and coordinated disclosure
We will assess reports, prioritise confirmed issues according to risk and communicate with reachable reporters about relevant progress. We may need additional information. No fixed acknowledgement or remediation deadline is guaranteed, and a report does not guarantee that a particular change will be made.
Please coordinate disclosure with us and allow a reasonable opportunity to investigate and mitigate the issue. Discuss an appropriate disclosure date rather than publishing customer data or active exploit details. We do not require a non-disclosure agreement simply to receive a report.
Flowpane will not initiate legal action against good-faith research that complies with this policy and the law. We cannot grant permission on behalf of third parties or bind their actions. If you make an accidental discovery, stop and report it promptly; explain any unintended access honestly.
Recognition, without financial rewards
We appreciate responsible reports. With your permission, we can acknowledge your contribution by your chosen name or handle after remediation and coordinated disclosure. Credit is optional; we will not publish your identity without your agreement.
This is a vulnerability disclosure programme, not a paid bug bounty programme. We do not offer monetary rewards, fees or compensation for reports, testing or remediation suggestions. Submission does not create an entitlement to payment, employment or a commercial engagement.