Responsible disclosure

Last updated 25 August 2026

We welcome reports from security researchers and commit to handling them quickly and without legal threat for good-faith research.

How to report

Send the report through the security disclosure page. Include reproduction steps, affected endpoints or components, impact, and any proof-of-concept. One issue per report keeps triage fast.

Our commitments

- Acknowledgement within two business days.

- A triage decision and severity assessment within five business days.

- Progress updates until resolution, and credit in our acknowledgements if you want it.

In scope

The Flowarden web application, its public API endpoints, authentication and session handling, authorisation and row-level security boundaries, and our published infrastructure.

Out of scope

Denial-of-service and volumetric testing, social engineering of staff or users, physical attacks, reports generated solely by automated scanners without demonstrated impact, missing best-practice headers with no exploit path, and vulnerabilities in third-party services — report those to the vendor.

Rules of engagement

Test only against your own account, do not access or modify other users' data, do not exfiltrate data beyond what is needed to prove impact, and give us reasonable time to remediate before public disclosure.

// STILL NEED A HAND?

We reply to every message, usually within a business day.

Contact support