Skip to main content

Coordinated disclosure

Report a security vulnerability

LigoFlow investigates good-faith reports affecting authentication, tenant isolation, encryption, integrations, public APIs, or customer data protection.

Send the report

Email security@ligoflow.ai with affected URLs, impact, reproduction steps, and any supporting logs or screenshots.

Triage the report

The security owner reviews the report, preserves the relevant evidence, and coordinates follow-up through the security process.

Remediate and verify

Confirmed issues are tracked through fix, regression tests, deployment, and retest before disclosure closure.

Safe-harbor boundaries

Keep testing limited to accounts, workspaces, and data you own or have explicit permission to use. Avoid service disruption, persistence, exfiltration, social engineering, spam, and destructive actions.

Do not access, modify, or disclose customer data. If a test exposes sensitive data, stop immediately, preserve only the minimum evidence, and include that context in the report.