Этот материал пока доступен только на английском языке.
How to report
Send your report to [email protected]. Our machine-readable contact details are in /.well-known/security.txt.
- The affected domain or endpoint
- The vulnerability type and potential impact
- Step-by-step reproduction instructions
- Proof of concept if available (screenshots, request/response samples)
Scope
| In scope | Out of scope |
|---|---|
| logflare.net and its subdomains | Social engineering and physical attacks |
| The client portal (once live) | Denial of service (DoS / DDoS) testing |
| Vulnerabilities in third-party services | |
| Automated scanner output without demonstrated impact |
Our commitments
- 01
Prompt response
We acknowledge your report and share how we will assess it.
- 02
Transparency
We keep you informed about the fix status and expected timeline.
- 03
Recognition
With your permission, we credit you by name once the issue is fixed.
- 04
Safe harbor
We will not pursue legal action for good-faith research that follows this policy.
See the Responsible Disclosure Policy for the detailed rules.