Security
Responsible disclosure
We appreciate researchers and customers who report security issues privately so we can protect firm data. Please do not publicly disclose issues until we have confirmed a fix or agreed on a timeline.
How to report
- Email Support@GAASFlow.com with subject line Security report.
- Describe the issue, affected URL or API, and clear steps to reproduce.
- Include impact assessment if known (auth bypass, tenant isolation, data exposure).
- Allow a reasonable time for investigation before public discussion.
Please avoid
- Accessing or modifying other firms’ data beyond what is needed to prove a bug
- Denial-of-service testing against production without written approval
- Social engineering of customers or employees
- Publishing exploit code before coordination
What we commit to
- Acknowledge receipt when feasible
- Investigate and remediate confirmed issues with priority based on risk
- Credit researchers who request acknowledgment (optional)