FlowPSA legal
Responsible Disclosure
Effective date and version: September 23, 2026 (2026-09-23)
Report a concern
FlowPSA holds client records, time, and invoices, so we take reports seriously. If you believe you found a security issue in this website or a FlowPSA product surface, email clientsupport@flowdevs.io with “Security report” in the subject. Include reproduction steps, the affected URL or component, and the potential impact. Do not include secrets or exploit payloads in the first message.
Please do not
Access another person’s data, interrupt service, social-engineer people, run automated high-volume scans, or exploit a vulnerability beyond what is needed to demonstrate the issue safely.
Our commitment
We review good-faith reports promptly, acknowledge receipt when we can, and work to understand and address validated issues. We do not authorize testing that could damage systems, expose data, or affect other users.