Vulnerability Disclosure
We invite researchers and security professionals to participate in our Vulnerability Disclosure Program (VDP), where you can submit any identified vulnerabilities. Your expertise is essential in helping us enhance the security of our systems and protect our users. We greatly value your contributions and commitment to maintaining a safe digital environment. Participants are encouraged to submit detailed reports of any discovered vulnerabilities, including relevant evidence, to security@fluxxlabs.com.
Scope: This program covers all functionality and endpoints of the Fluxx grant management application hosted on the `*.fluxx.io` domain, including both Standard Cloud and Enterprise Cloud environments. Testing must be non-destructive and not disrupt our services or impact other customers.
Out of Scope: Dangling DNS records are explicitly out of scope. Additionally, findings related to systems not owned or operated by Fluxx, or that rely solely on automated scanning results without demonstrable impact, may not be considered actionable.
Our security team is committed to reviewing and addressing submissions promptly and will engage in a responsible disclosure process with all participants.