Security
Responsible disclosure
We take security seriously at Flare. If you have discovered a security vulnerability, we appreciate your help in disclosing it responsibly.
How to report a vulnerability
Please email security@flare.co with details of the vulnerability. Include:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any proof-of-concept code, if applicable
Our commitment
Acknowledgment: we will acknowledge your report within 48 hours.
Communication: we will keep you informed of our progress.
Credit: with your permission, we will credit you in our security acknowledgments.
No legal action: we will not pursue legal action against researchers who follow responsible disclosure practices.
Scope
Our security program covers:
- flare.co and all subdomains
- API endpoints
- Authentication and authorization systems
- Data storage and transmission
Out of scope
Please avoid:
- Social engineering attacks
- Physical security testing
- Denial of service attacks
- Testing on accounts you do not own