How to Report
Send all security concerns to contact@agentflow-enterprise.com. This is the only supported reporting channel. Do not open a GitHub issue for security-related findings.
What to Include in Your Report
To help the team understand and address your concern quickly, include the following in your message:- A clear summary of the security concern — describe what you found and why it matters
- The affected page or file — link to or name the specific public file, page, or URL involved
- Reproduction steps — if the issue can be demonstrated, explain how to reproduce it
- Recommended remediation — if you have a suggested fix or mitigation, include it
Scope
Not every security question falls within the scope of this public disclosure process. Use the table below to determine whether your concern is in scope before reaching out.| In Scope | Out of Scope |
|---|---|
| Accidental exposure of sensitive information in public files | Requests for private source code or internal implementation details |
| Misleading or inaccurate security statements in documentation | Attempts to bypass access controls or authentication |
| Unsafe public documentation that could mislead security reviewers | Attacks against third-party services (Supabase, Stripe, OpenAI, Vercel, etc.) |
| Broken links that could misdirect security-focused buyers | Social engineering attempts targeting AgentFlow team members |
| Documentation that exposes internal details unintentionally | Speculative reports without practical, demonstrable impact |
Do Not Post Publicly
This applies even if the issue seems minor. The team will work with you to determine the right response and, where appropriate, acknowledge your contribution.Response Expectations
After you send a report to contact@agentflow-enterprise.com, you can expect:- Acknowledgement — the team will confirm receipt and that your report is being reviewed
- Triage — the team will assess the severity and scope of the concern
- Follow-up — if more information is needed, the team will reach out directly
Bug Bounty
There is no public bug bounty program currently. The team appreciates responsible disclosure and will acknowledge valid contributions, but no financial reward is offered at this time.Related: Security Overview · Data Handling