Vulnerability Disclosure Policy
DRAFT v1.0 — prepared for review by qualified counsel before publication. Replace bracketed placeholders.
Version: 1.0 Effective date: [EFFECTIVE DATE] Published at: flowagenci.com/legal/security
[FLOWAGENCI LLC LEGAL NAME] ("FlowAgenci", "we") welcomes reports from security researchers. This policy explains how to report a vulnerability in Flow and what you can expect from us.
1. How to report
Email security@flowagenci.com with:
- a description of the issue and its impact
- the steps to reproduce it (URLs, requests, accounts involved)
- your name or handle, if you would like to be credited
Our contact details are also published at /.well-known/security.txt on every Flow host.
2. Scope
In scope:
- the Flow application (app.flowagenci.com)
- Client Portals (
<slug>.flowagenci.com) - public forms (
/f/*) - the flowagenci.com website
Out of scope:
- Customers' custom domains and the content they host
- denial-of-service or volumetric testing
- social engineering and physical attacks
- reports from automated scanners with no demonstrated impact
- missing security headers without a working exploit
3. Rules
- Only test against accounts and organizations you own. Never access, change or delete another Customer's data. If you reach it by accident, stop, and tell us what you saw.
- Don't degrade the Service for others.
- Give us reasonable time to fix the issue before you disclose it publicly. We suggest 90 days.
4. What you can expect
- We acknowledge your report within 3 business days.
- We send an initial assessment within 10 business days.
- We tell you when the issue is fixed and, if you wish, credit you.
5. Safe harbor
If you act in good faith and follow this policy, we will not pursue legal action against you for your research. We will also not ask a law-enforcement agency to do so.