Security
Reporting a vulnerability
If you discover a security vulnerability in Fleuron, report it by email to security@fleuron.md with the subject line “Security disclosure.”
Please include:
- A description of the vulnerability and where it exists
- Steps to reproduce it
- The potential impact you see
- Any supporting material (screenshots, proof-of-concept code)
You will receive an acknowledgment within 48 hours. Confirmed vulnerabilities are addressed within 14 days for critical issues and 90 days for others.
What Fleuron asks
- Give a reasonable amount of time to fix the issue before disclosing it publicly
- Do not access or modify other users’ data
- Do not disrupt the service for others
- Act in good faith
What you can expect
- No legal action against researchers who follow these guidelines
- Your report kept confidential if you prefer
Scope
In scope: fleuron.md and all subdomains, the Fleuron API, and the collaboration server.
Out of scope: attacks that require physical access to a device, social engineering, denial-of-service testing against the production service, and issues in third-party services Fleuron depends on. Report those to the respective vendor.