Flagsmith · Vulnerability Disclosure
Flagsmith Vulnerability Disclosure
Vulnerability disclosure
Flagsmith runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
Feature FlagsRemote ConfigRelease ManagementA/B TestingExperimentationSegmentationDeveloper ToolsDevOpsOpen SourceSoftware-as-a-ServiceMCPAgent Ready
Program: Hackerone
Disclosure Policy
Security Contact
Contact
emailsupport@flagsmith.com
Contact
noteWritten in the policy as "support[at]flagsmith[dot]com" (obfuscated against scrapers). There is no dedicated security@ address and no PGP key.
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.