AuditFlow ← Back to home

Security & Responsible Disclosure

Effective: 2026-06-06 · Version 1

This page tells security researchers, customers, and members of the public how to report a vulnerability in AuditFlow to us, what to expect when they do, and the protection from legal action that we extend to good-faith researchers.

How to reach us: info@audit-flow.net. We acknowledge every valid report within 1 business day.

1. Scope

In scope:

Out of scope:

2. What we ask of researchers

To remain protected under the safe-harbor provisions in section 4 below, please:

3. What to include in your report

4. Safe harbor

We will not pursue civil or criminal action against, or refer law enforcement to, any researcher who:

If your research is conducted in line with the above, we consider it authorised under our Terms of Service and any applicable computer-misuse law in the jurisdictions where we operate. We will say so in writing if you ask.

5. Our commitment to you

When you submit a valid report, we will:

  1. Acknowledge receipt within 1 business day.
  2. Give you a triage outcome (accepted / duplicate / out-of-scope / not-a-vulnerability) within 5 business days.
  3. Keep you informed of remediation progress at a cadence appropriate to the severity. Critical and high-severity findings get a weekly update; medium gets a biweekly update; low gets an update when the fix lands.
  4. Credit you on the public change log when the fix ships, unless you ask us not to.
  5. Where appropriate, request a CVE ID through the GitHub Security Advisory process.

6. Bug bounty

We do not currently operate a paid bug-bounty programme. We are working toward one in 2027 — see the security maturity roadmap for the planned rollout. Until then, we credit responsible disclosures publicly and reach out personally to researchers we want to keep talking to.

7. PGP / encrypted communication

We do not yet publish a PGP key for info@audit-flow.net. If you have a finding that materially benefits from encrypted transport (for example, the report includes live credentials or exploit code), reply to our acknowledgement requesting an encrypted channel and we will set one up before you send details.

8. Coordinated disclosure timeline

Once a fix has shipped to production, we publish:

9. Contact

info@audit-flow.net — all security communications.

See also: Trust & Security · Privacy Policy · Change log