# Flovanta Security Policy # https://securitytxt.org — RFC 9116 compliant Contact: mailto:security@flovanta.com Expires: 2027-05-08T00:00:00.000Z Encryption: https://www.flovanta.com/.well-known/pgp-key.txt Acknowledgments: https://www.flovanta.com/security/hall-of-fame Preferred-Languages: en, es Canonical: https://www.flovanta.com/.well-known/security.txt Policy: https://www.flovanta.com/security/disclosure-policy # ------------------------------------------------------- # Scope # ------------------------------------------------------- # In scope: # - https://www.flovanta.com # - https://app.flovanta.com # - Flovanta API endpoints # - Flovanta mobile/web clients # # Out of scope: # - Social engineering attacks # - Physical security # - Third-party services (Stripe, Twilio, etc.) # - Denial of service attacks # - Findings from automated scanners without validation # -------------------------------------------------------