How to report a vulnerability
Send your findings to security@flovanta.com. Include a clear description of the issue, steps to reproduce it, and the potential impact. You can also reference our machine-readable policy at /.well-known/security.txt.
Please do not disclose the issue publicly until we've had a chance to investigate and release a fix. We'll keep you informed as the report moves through triage and remediation.
What we protect
Flovanta is a multi-tenant SaaS platform. Our highest-priority security concern is tenant isolation: agency receivables, client, invoice, and payment-status data must remain separated by account.
Scope
Please only test against your own account. Do not attempt to access other users' data, run automated scanners without prior coordination, or perform denial-of-service testing.
- flovanta.com and subdomains
- app.flovanta.com (web application)
- Flovanta REST API endpoints
- Authentication and session logic
- Tenant isolation and IDOR vulnerabilities
- File upload security
- Payment flow logic
- Social engineering attacks
- Physical security
- Third-party services (Stripe, Twilio)
- Denial of service attacks
- Automated scanner results without manual validation
- Missing security headers without exploit PoC
- Self-XSS requiring victim interaction
How we prioritise findings
We assess severity based on exploitability and potential impact on agency data.
What happens after you report
We aim to confirm receipt of your report within 48 hours and assign it an internal tracking reference.
Our engineering team reproduces the issue, assesses severity, and aims to confirm scope within 7 days.
We develop and deploy a fix. For critical issues, we may ask you to verify the patch resolves the finding.
With your permission, we can credit you in our security acknowledgements. Coordinated public disclosure happens after the fix is live.
Found something?
Email us directly with reproduction steps and impact. We aim to acknowledge reports within 48 hours.