Security

Responsible disclosure

We appreciate researchers and customers who report security issues privately so we can protect firm data. Please do not publicly disclose issues until we have confirmed a fix or agreed on a timeline.

How to report

  1. Email Support@GAASFlow.com with subject line Security report.
  2. Describe the issue, affected URL or API, and clear steps to reproduce.
  3. Include impact assessment if known (auth bypass, tenant isolation, data exposure).
  4. Allow a reasonable time for investigation before public discussion.

Please avoid

  • Accessing or modifying other firms’ data beyond what is needed to prove a bug
  • Denial-of-service testing against production without written approval
  • Social engineering of customers or employees
  • Publishing exploit code before coordination

What we commit to

  • Acknowledge receipt when feasible
  • Investigate and remediate confirmed issues with priority based on risk
  • Credit researchers who request acknowledgment (optional)

Trust center · Security controls · security.txt