Coordinated disclosure

Vulnerability disclosure

The Sentinel Flow welcomes reports from security researchers and customers who identify a potential vulnerability in the platform. This policy describes how to report one, what to expect in response, and what activity is out of scope.

Where to send a report

Email security@thesentinelflow.com with the subject line [Security Report]. Please do not open a public issue, blog post, or social-media thread before we have acknowledged the report.

What to include

  • A clear description of the issue and its potential impact
  • The affected URL, endpoint, or workflow
  • Steps to reproduce, in order
  • Any relevant request/response snippets — redact any personal data
  • Your name or handle if you want to be credited

Out of scope

  • Automated scanning that degrades production performance
  • Denial-of-service, spam, or brute-force testing
  • Accessing, modifying, or exfiltrating data that does not belong to you
  • Social engineering of Sentinel Flow staff, customers, or vendors
  • Physical testing of infrastructure or offices
  • Publicly disclosing an issue before we have had a reasonable window to remediate

Response timeline

Acknowledgement

We aim to acknowledge good-faith reports within 3 business days.

Triage

Initial severity assessment and reproduction within 10 business days.

Remediation

Targeted fix or mitigation on a timeline that matches severity.

Closure

We confirm the fix with you and, where appropriate, credit the reporter.

Safe harbor

If you make a good-faith effort to comply with this policy — avoid privacy violations, destruction of data, and interruption or degradation of the service — we will consider your research authorized, will not pursue or support legal action against you, and will work with you to understand and resolve the issue quickly.

For general product or account questions, please use Support instead.