
Security & Responsible Disclosure
Security at finFlow
finFlow is a financial administration platform provided by Collabify Limited. We treat the confidentiality, integrity and availability of customer information as part of the design and operation of the service.
Our security controls include account and company-scoped access controls, support for two-factor authentication, secure password requirements, request rate limiting on sensitive flows, and security checks within our software delivery process. We review and improve these controls as finFlow evolves.
Report a security issue
If you believe you have found a vulnerability in finFlow, email hello@collabify.net with the subject finFlow security report.
Please include the affected URL or feature, clear reproduction steps, the impact you believe is possible, and any proof-of-concept material needed to reproduce the issue safely.
Our machine-readable disclosure contact is also published at /.well-known/security.txt.
Responsible testing guidelines
We welcome good-faith security research that is designed to identify and report vulnerabilities without causing harm. When testing finFlow:
- use accounts and data that you own or are explicitly authorised to test;
- do not access, retain, alter or disclose another customer's data;
- stop testing and report the issue if you unexpectedly gain access to sensitive information;
- do not perform denial-of-service, destructive, high-volume or availability-impacting tests;
- do not use social engineering, phishing, physical attacks or attacks against Collabify staff or customers;
- do not test third-party services or infrastructure that finFlow integrates with unless you have separate permission from that provider.
Scope
This disclosure guidance applies to finFlow services and software operated by Collabify Limited, including the finFlow web application and its first-party APIs. Third-party payment processors, government services, app stores and other external services are outside this policy and must be reported to the relevant provider.
What happens after a report
We will review credible reports, reproduce and assess the issue, prioritise remediation according to risk, and coordinate communication with the reporter where appropriate. Please allow us a reasonable opportunity to investigate and correct a vulnerability before publishing details that could put finFlow users at risk.
Security enquiries
For security questions that are not vulnerability reports, contact hello@collabify.net.