We welcome reports from security researchers and commit to handling them quickly and without legal threat for good-faith research.
How to report
Send the report through the security disclosure page. Include reproduction steps, affected endpoints or components, impact, and any proof-of-concept. One issue per report keeps triage fast.
Our commitments
- Acknowledgement within two business days.
- A triage decision and severity assessment within five business days.
- Progress updates until resolution, and credit in our acknowledgements if you want it.
In scope
The Flowarden web application, its public API endpoints, authentication and session handling, authorisation and row-level security boundaries, and our published infrastructure.
Out of scope
Denial-of-service and volumetric testing, social engineering of staff or users, physical attacks, reports generated solely by automated scanners without demonstrated impact, missing best-practice headers with no exploit path, and vulnerabilities in third-party services — report those to the vendor.
Rules of engagement
Test only against your own account, do not access or modify other users' data, do not exfiltrate data beyond what is needed to prove impact, and give us reasonable time to remediate before public disclosure.