SECURITY · RESPONSIBLE DISCLOSURE

Responsible vulnerability disclosure

Flovanta handles receivables data for marketing agencies. If you've found a vulnerability, we want to hear from you privately, directly, and with enough detail for us to investigate.

How to report a vulnerability

Send your findings to security@flovanta.com. Include a clear description of the issue, steps to reproduce it, and the potential impact. You can also reference our machine-readable policy at /.well-known/security.txt.

Please do not disclose the issue publicly until we've had a chance to investigate and release a fix. We'll keep you informed as the report moves through triage and remediation.

48h
Target initial acknowledgement
7d
Target severity assessment
30d
Target fix window for critical and high severity issues
90d
Target fix window for medium and low severity issues

What we protect

Flovanta is a multi-tenant SaaS platform. Our highest-priority security concern is tenant isolation: agency receivables, client, invoice, and payment-status data must remain separated by account.

Tenant isolationAgency-level data separation is a primary security control
AuthenticationAccount access controls protect user sessions and roles
Payment dataStripe-handled payment processing, no raw card data stored
Invoice & client dataReceivables data is handled through application and database access controls
File uploadsBranding assets validated and sandboxed on upload
API endpointsAPI behavior is validated and reviewed for abuse and injection risks

Scope

Please only test against your own account. Do not attempt to access other users' data, run automated scanners without prior coordination, or perform denial-of-service testing.

✓ In scope
  • flovanta.com and subdomains
  • app.flovanta.com (web application)
  • Flovanta REST API endpoints
  • Authentication and session logic
  • Tenant isolation and IDOR vulnerabilities
  • File upload security
  • Payment flow logic
— Out of scope
  • Social engineering attacks
  • Physical security
  • Third-party services (Stripe, Twilio)
  • Denial of service attacks
  • Automated scanner results without manual validation
  • Missing security headers without exploit PoC
  • Self-XSS requiring victim interaction

How we prioritise findings

We assess severity based on exploitability and potential impact on agency data.

Critical≤ 24hTenant isolation breach, authentication bypass, mass data exposure
High≤ 7dIDOR, privilege escalation, sensitive data leakage, payment flow manipulation
Medium≤ 30dStored XSS, CSRF with meaningful impact, insecure file handling
Low≤ 90dInformation disclosure, rate limiting gaps, minor configuration issues

What happens after you report

01
Acknowledgement

We aim to confirm receipt of your report within 48 hours and assign it an internal tracking reference.

02
Triage & assessment

Our engineering team reproduces the issue, assesses severity, and aims to confirm scope within 7 days.

03
Fix & verification

We develop and deploy a fix. For critical issues, we may ask you to verify the patch resolves the finding.

04
Credit & disclosure

With your permission, we can credit you in our security acknowledgements. Coordinated public disclosure happens after the fix is live.


Found something?

Email us directly with reproduction steps and impact. We aim to acknowledge reports within 48 hours.

Report a vulnerability →