Reporting a security issue.
If you believe you have found a security vulnerability in Floxar, please tell us. Every report is read by a person, and we will work with you to understand and fix the issue.
Email security@floxar.com.
Send your report to security@floxar.com. It helps to include:
- A description of the issue and its potential impact
- The affected URL, endpoint or feature
- Steps to reproduce, with any proof-of-concept code or screenshots
- How we can reach you to follow up
Please include only the data needed to show the issue, and never include data that belongs to someone else.
What this covers.
Services operated by Floxar, including www.floxar.com, the Floxar application at www.floxar.com/in/, docs.floxar.com, login.floxar.com, tokens.floxar.com, api.floxar.com, mcp.floxar.com, and the Floxar Secrets Vault at vault.floxar.com.
Issues in third-party services that Floxar uses, such as Amazon Web Services, Google or Anthropic, should be reported to those providers. Reports that show no security impact, such as missing headers or banner disclosure on their own, are usually out of scope.
What we ask, and what we commit to.
-
Test only what you are allowed to
Use accounts you own or have permission to test. If you reach data that is not yours, stop, do not keep or share it, and tell us.
-
We acknowledge quickly
We aim to acknowledge every report within three business days and to keep you informed until the issue is resolved.
-
Do no harm
No denial of service, spam, social engineering or physical attacks, and no testing that degrades the service for others.
-
Good-faith research is welcome
We will not pursue or support legal action against research carried out in good faith and in line with this page.
-
Give us time to fix it
Please keep the issue confidential until we have had a reasonable chance to fix it, and coordinate disclosure with us.
-
Credit where it is due
With your permission, we are glad to credit you once the fix is live. Floxar does not currently run a paid bug bounty.
Machine-readable contact details are published at /.well-known/security.txt. For how we handle personal information, see the Privacy Policy.
Found something?
Tell us, even if you are not sure it is a vulnerability.