finFlow Logo

Security & Responsible Disclosure

Last updated 4 October 2026

Security at finFlow

finFlow is a financial administration platform provided by Collabify Limited. We treat the confidentiality, integrity and availability of customer information as part of the design and operation of the service.

Our security controls include account and company-scoped access controls, support for two-factor authentication, secure password requirements, request rate limiting on sensitive flows, and security checks within our software delivery process. We review and improve these controls as finFlow evolves.

Report a security issue

If you believe you have found a vulnerability in finFlow, email hello@collabify.net with the subject finFlow security report.

Please include the affected URL or feature, clear reproduction steps, the impact you believe is possible, and any proof-of-concept material needed to reproduce the issue safely.

Our machine-readable disclosure contact is also published at /.well-known/security.txt.

Responsible testing guidelines

We welcome good-faith security research that is designed to identify and report vulnerabilities without causing harm. When testing finFlow:

  • use accounts and data that you own or are explicitly authorised to test;
  • do not access, retain, alter or disclose another customer's data;
  • stop testing and report the issue if you unexpectedly gain access to sensitive information;
  • do not perform denial-of-service, destructive, high-volume or availability-impacting tests;
  • do not use social engineering, phishing, physical attacks or attacks against Collabify staff or customers;
  • do not test third-party services or infrastructure that finFlow integrates with unless you have separate permission from that provider.

Scope

This disclosure guidance applies to finFlow services and software operated by Collabify Limited, including the finFlow web application and its first-party APIs. Third-party payment processors, government services, app stores and other external services are outside this policy and must be reported to the relevant provider.

What happens after a report

We will review credible reports, reproduce and assess the issue, prioritise remediation according to risk, and coordinate communication with the reporter where appropriate. Please allow us a reasonable opportunity to investigate and correct a vulnerability before publishing details that could put finFlow users at risk.

Security enquiries

For security questions that are not vulnerability reports, contact hello@collabify.net.

This page describes our vulnerability disclosure process. It is not permission to access data or systems beyond the accounts and resources you are authorised to use.