Skip to content

Security: lnflash/flash-client

SECURITY.md

Security Policy

Flash takes the security of our software and our users seriously, and we appreciate responsible disclosure.

Reporting a Vulnerability

Please email security@getflash.io.

Include as much of the following as you can:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (proof of concept, affected versions or endpoints)
  • Any suggested remediation

Please do not open a public GitHub issue for security vulnerabilities.

What to Expect

  • We aim to acknowledge reports within 2 business days.
  • We will keep you informed as we investigate and remediate.
  • Please allow us a reasonable window to fix the issue before public disclosure.

Scope

This policy applies to all public repositories in the lnflash organization and to the Flash app and services (getflash.io, flashapp.me).

There aren't any published security advisories