Vulnerability Disclosure Policy

Introduction

PermitFlow is committed to ensuring the security of our customers and their data. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.

This policy describes what systems and types of research are covered, how to send us vulnerability reports, and how long we ask you to wait before publicly disclosing vulnerabilities. We encourage you to contact us to report potential vulnerabilities in our systems.

Authorization

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and PermitFlow will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

We consider research conducted under this policy to be authorized conduct under the Computer Fraud and Abuse Act (and applicable state equivalents), and we waive any claim under the Digital Millennium Copyright Act for circumvention of technology controls to the extent such circumvention was necessary to conduct research under this policy.

Guidelines

Under this policy, "research" means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly. Our default coordinated disclosure window is 90 days from triage; we're happy to discuss timing.
  • Do not submit a high volume of low-quality reports.

Once you've established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Only test against accounts you own or have explicit permission to use. Never access, modify, or delete data belonging to other PermitFlow customers.

Test methods

The following test methods are not authorized:

  • Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data
  • Physical testing (e.g., office access, open doors, tailgating), social engineering (e.g., phishing, vishing), or any other non-technical vulnerability testing
  • High-volume automated scanning that could degrade service

Scope

This policy applies to the following systems and services:

  • app.permitflow.com
  • api.permitflow.com
  • live.permitflow.com

Any service not expressly listed above, such as any connected services, is excluded from scope and is not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy's scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren't sure whether a system is in scope or not, contact us at security@permitflow.com before starting your research.

Though we develop and maintain other internet-accessible systems and services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document.

Reporting a vulnerability

Reports are accepted via email at security@permitflow.com. Reports may be submitted anonymously. If you share contact information, we will acknowledge receipt of your report within 3 business days.

If you'd like to encrypt your report, our PGP key is available at keys.openpgp.org (fingerprint: 18E2 B537 B605 86DB F0A5 B1E6 E0C9 7B13 C111 7438).

What we would like to see from you

To help us triage and prioritize submissions, we recommend that your reports:

  • Describe the location the vulnerability was discovered (URL, endpoint, or component) and the potential impact of exploitation
  • Offer a detailed description of the steps needed to reproduce the vulnerability (proof-of-concept scripts, screenshots, or request/response pairs are helpful)
  • Include any accounts, IPs, or timestamps involved in your testing, so we can correlate logs
  • Be in English, if possible

What you can expect from us

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible:

  • Within 3 business days, we will acknowledge that your report has been received.
  • Within 10 business days, we will confirm the existence of the vulnerability to the best of our ability and give you an initial assessment.
  • We will be as transparent as possible about the steps we are taking during the remediation process, including on issues or challenges that may delay resolution, and we'll notify you when the issue is resolved.
  • We will maintain an open dialogue to discuss issues.
  • With your permission, we'll credit you for the finding. If you prefer anonymity, we'll respect that.

Non-qualifying findings

We appreciate all reports, but the following are generally not accepted as vulnerabilities unless accompanied by a demonstrated, meaningful security impact:

  • SPF, DKIM, or DMARC configuration observations without a working spoofing demonstration
  • Clickjacking on pages with no sensitive actions
  • Missing security headers that don't lead to a concrete exploit
  • Self-XSS or issues requiring an implausible level of victim interaction
  • Software version disclosure, banner grabbing, or descriptive error messages
  • Missing rate limiting without demonstrated abuse impact
  • CSRF on forms with no security consequence (e.g., logout)
  • Results from automated scanners without validation or a proof of concept

Rewards

This is a vulnerability disclosure program, not a formal bug bounty. That said, we do pay bounties at our sole discretion for findings we assess as high or critical severity. Severity is determined by PermitFlow based on real-world impact to our customers and their data, not by scanner output or CVSS score alone. Reward amounts, eligibility, and severity classification are decided by us on a case-by-case basis, and submission of a report does not create any entitlement to payment. Findings listed under non-qualifying findings above are not eligible for rewards.

Duplicate reports are rewarded only for the first submission. To receive payment, you must be able to legally receive it (e.g., not be subject to sanctions) and may need to provide tax documentation.

Questions

Questions regarding this policy may be sent to security@permitflow.com. We also invite you to contact us with suggestions for improving this policy.

Last updated: July 29, 2026

Permitting without the headache

Book a Demo