About the reward, up front

This is a small operation. We cannot pay the kind of bounty a large company pays, and we are not going to pretend otherwise or offer you a token amount that wastes your time.

What we can offer for a valid, relevant report is One year of FlowReader Pro, free, plus credit in the release notes under whatever name you choose, or none at all if you would rather stay anonymous. If that is not worth your time, we completely understand, and we would still rather you told us.

  • One report, one reward. Duplicates go to whoever reported first, and we will tell you if yours was one.
  • The report has to be new, in scope, and demonstrate real impact. We decide that, and we will explain the reasoning either way.
  • We cannot issue rewards where sanctions or export-control law prevents it, or to anyone on a relevant sanctions list.
  • Any tax on the reward is yours. It is a year of a EUR 7.99 subscription, so this is unlikely to be interesting, but we are not going to imply otherwise.

What happens after you send it

  1. 01

    You report it privately

    Use the form on this page. Include the affected version and platform, what you did, what happened, and why it matters. Do not open a public issue, and do not post it anywhere else first.

  2. 02

    We acknowledge within five business days

    A person reads it and replies. If you have not heard anything in that window, assume it went astray and send it again. That is a failure on our side, not a hint to escalate publicly.

  3. 03

    We classify and fix

    We assess severity, agree a remediation timeline with you, and keep you updated as it moves. Reports involving credential theft or remote code execution are treated as urgent.

  4. 04

    We coordinate disclosure

    Once a fix has shipped and users have had a reasonable chance to update, you are free to write about it. We will credit you by whatever name you prefer, or not at all if you would rather stay anonymous.

In scope

  • The browser extensions for Chromium browsers and Firefox
  • The desktop application
  • The FlowReader website
  • The optional server-side services: sync, newsletter ingestion, server-side Flows and subscription handling
  • Anything that lets one account reach another account’s data
  • Anything that gets local reading data off a device without the user asking

Not in scope

Listed so you do not spend time on something we will close.

  • Findings from automated scanners with no demonstrated impact
  • Missing security headers or cookie flags with no exploitable consequence
  • Rate limiting or brute force on endpoints with no sensitive effect
  • Social engineering, phishing, or physical access to someone’s unlocked device
  • Denial of service, traffic flooding, or anything that degrades the service for real users
  • Vulnerabilities in third-party services we do not control. Report those to their owners
  • Reports that require a user to install a malicious build of FlowReader

Ground rules

Stay inside these and your research is authorised. The safe harbour below says what that means in the terms that actually matter to you.

  • Use your own account and your own test data. Never access, modify or retain anyone else’s.
  • Stop as soon as you have demonstrated the issue. Do not pivot further into the system.
  • Do not run denial-of-service tests, or anything that degrades the service for other people.
  • Do not include production credentials or real user content in your report.
  • Give us a reasonable chance to fix it before writing publicly.

Safe harbour

A promise not to be difficult is not much use when the exposure is a named statute. This is the commitment in the terms a researcher is actually weighing.

  • We authorise the security research described in the ground rules above. Access carried out within them is access with our permission. That is the point of saying so here rather than only promising not to complain about it later.
  • We will not bring or support a civil claim or a criminal complaint against you for research that stays inside those rules, including under Norway’s straffeloven §§ 204–206, the US Computer Fraud and Abuse Act and DMCA § 1201, and the UK Computer Misuse Act 1990.
  • If a third party takes action against you over research we authorised, tell us and we will confirm to them, in writing, that it was authorised.
  • If you break a rule by accident and tell us promptly, we will treat that as good faith. This is about intent, not perfection. A researcher who stops and reports has done the right thing.
  • We cannot waive the rights of anyone else. If your testing reaches a third party’s system or another user’s data, this safe harbour does not cover it, which is why the rules say to stop.

Report a vulnerability

This goes straight to the security mailbox, not to a public tracker and not to a support queue. Acknowledged within five business days.

Do not include credentials, access tokens, or real user content in this form. If a proof of concept needs them, say so and we will arrange a secure channel.

Used only to reply to this message.

Affected version and platform, the steps to reproduce it, what happens, and why it matters. Never include production credentials or anyone’s real content.

Spam check

This one check is run by Cloudflare. It sets no cookie and does not track you across sites.

No account needed, and nothing is stored on this site. The message is emailed, and that is all.