FlowRMM legal

Responsible Disclosure

Effective date and version: September 5, 2026 (2026-09-05)

Report a concern

Responsible disclosure is a baseline expectation for any vendor with an agent on your endpoints. If you believe you found a security issue in this marketing site or a FlowRMM product surface, submit a concise report through the Cohort 01 form with “Security report” in the evaluation field. Include reproduction steps, the affected URL or component, and the potential impact. Do not include secrets or exploit payloads in the first message.

Please do not

Do not access another person’s data, interrupt service, social-engineer people, use automated high-volume scans, or exploit a vulnerability beyond what is needed to demonstrate the issue safely.

Our commitment

We build tooling that runs with privilege on other people’s machines. We review good-faith reports promptly, acknowledge receipt when we can, and work to understand and address validated issues. We do not authorize testing that could damage systems, expose data, or affect other users.