Coordinated disclosure

Report a security vulnerability

LigoFlow investigates good-faith reports affecting authentication, tenant isolation, encryption, integrations, public APIs, or customer data protection.

Send the report

Email security@ligoflow.ai with affected URLs, impact, reproduction steps, and any supporting logs or screenshots.

Triage and acknowledge

The platform security owner triages severity, preserves evidence, and targets acknowledgement within two business days.

Remediate and verify

Confirmed issues are tracked through fix, regression tests, deployment, and retest before disclosure closure.

Safe-harbor boundaries

Keep testing limited to accounts, workspaces, and data you own or have explicit permission to use. Avoid service disruption, persistence, exfiltration, social engineering, spam, and destructive actions.

Do not access, modify, or disclose customer data. If a test exposes sensitive data, stop immediately, preserve only the minimum evidence, and include that context in the report.