Flash takes the security of our software and our users seriously, and we appreciate responsible disclosure.
Please email security@getflash.io.
Include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof of concept, affected versions or endpoints)
- Any suggested remediation
Please do not open a public GitHub issue for security vulnerabilities.
- We aim to acknowledge reports within 2 business days.
- We will keep you informed as we investigate and remediate.
- Please allow us a reasonable window to fix the issue before public disclosure.
This policy applies to all public repositories in the lnflash organization and to the Flash app and services (getflash.io, flashapp.me).