Security

Responsible disclosure

We take security seriously at Flare. If you have discovered a security vulnerability, we appreciate your help in disclosing it responsibly.

How to report a vulnerability

Please email security@flare.co with details of the vulnerability. Include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Any proof-of-concept code, if applicable

Our commitment

Acknowledgment: we will acknowledge your report within 48 hours.

Communication: we will keep you informed of our progress.

Credit: with your permission, we will credit you in our security acknowledgments.

No legal action: we will not pursue legal action against researchers who follow responsible disclosure practices.

Scope

Our security program covers:

  • flare.co and all subdomains
  • API endpoints
  • Authentication and authorization systems
  • Data storage and transmission

Out of scope

Please avoid:

  • Social engineering attacks
  • Physical security testing
  • Denial of service attacks
  • Testing on accounts you do not own