Loading LoadFlow Platform...
Loading LoadFlow Platform...
Last updated: July 2025
LoadFlow is committed to maintaining the security and privacy of our systems and our customers’ data. This Responsible Disclosure Policy outlines our approach to working with the security community and researchers who act in good faith to identify and report vulnerabilities.
If you believe you've discovered a security or privacy issue, we want to hear from you. We will investigate all valid reports and fix confirmed issues as quickly as possible.
We are committed to:
We believe that responsible security research benefits everyone, and we deeply appreciate your contributions to LoadFlow’s reliability and safety.
Anyone who discovers a security vulnerability — including security researchers, developers, customers, or ethical hackers — is welcome to report it. No prior approval or authorization is required to submit a report.
You must follow this policy and act in good faith to qualify for protection under our Safe Harbor terms (see Section 7).
We are primarily interested in high-impact, exploitable security vulnerabilities such as:
The following types of findings are not considered in-scope for this disclosure policy:
To report a vulnerability, please send a detailed email to:
Email: security@loadflowlogistics.com
Please include as much of the following as possible:
We recommend encrypting sensitive disclosures using a public PGP key (available upon request). Please do not share vulnerabilities through public channels like social media or GitHub.
If you act in good faith, comply with this policy, and avoid intentional harm or disruption, we will:
This protection applies only to ethical testing on in-scope systems that respects our rules and boundaries. LoadFlow reserves the right to revoke Safe Harbor in the case of malicious intent, fraud, or breach of confidentiality.
You must avoid:
All testing must be non-destructive, non-intrusive, and must not compromise user trust or data privacy.
LoadFlow commits to the following vulnerability disclosure process:
We may ask for extensions in complex cases. Researchers are encouraged to coordinate public disclosure responsibly. We support transparency but prefer disclosure after remediation whenever possible.
The following systems are considered in-scope for security testing under this policy:
The following are explicitly out-of-scope:
If multiple researchers report the same vulnerability, LoadFlow will consider only the first report that provides a complete, actionable reproduction. We reserve the right to acknowledge others who contribute meaningfully, but credit is not guaranteed for duplicates.
Please check this page and prior disclosures (if available) before submitting a known issue.
LoadFlow does not currently operate a public or paid bug bounty program. No monetary reward is promised for disclosures under this policy.
We may launch a formal bounty program in the future. At our discretion, we may offer swag, account credits, or public acknowledgment for particularly valuable reports. Participation in this policy is entirely voluntary.
You agree to:
Failure to follow these guidelines may result in disqualification from this policy and legal referral depending on severity.
If you discover a vulnerability in a third-party service used by LoadFlow (such as Stripe, Vercel, or DigitalOcean), we encourage you to report it directly to that provider through their own responsible disclosure program.
LoadFlow cannot accept responsibility or coordinate disclosure for platforms we do not control. We may, however, assist in verifying that LoadFlow systems were unaffected.
All reports must be submitted in English and in a clear, organized format. Please include steps to reproduce, affected components, and any relevant logs or headers. We accept reports by email only. Please do not contact us via social media, chat platforms, or public repositories.
LoadFlow expects all researchers participating in this program to:
We reserve the right to deny protection under this policy if researchers violate these principles or act maliciously.
LoadFlow may update this Responsible Disclosure Policy at any time. We encourage researchers to check back regularly for changes. Any updates will take effect upon publication.
Continued testing after a change is posted constitutes acceptance of the updated rules.