Security

How to report security issues and check what is in scope. Read the safe harbor terms before testing.

Last updated on August 12, 2026.

Reporting a vulnerability

Write to the security address on our company information page. Include the affected area, the realistic impact, and clear steps to reproduce it. Requests, logs, screenshots, and environment details help, as long as they don't expose unrelated personal data or secrets.

A report must show practical impact against a service we operate or a supported self-hosted release. Source review and local experiments can support that, but a theoretical issue with no realistic attack path isn't enough.

Scope

Applications, websites, services, and infrastructure operated by Fluxer are in scope, including fluxer.app, fluxer.com, fluxer.gg, fluxer.gift, fluxerapp.com, fluxer.dev, fluxer.tools, fluxerusercontent.com, fluxerstatic.com, fluxer.media, and their subdomains. Abuse of Fluxer features that enables unauthorised access, persistence, or data disclosure is also in scope, as are supported self-hosted releases when the issue reproduces without custom patches or unsupported configuration.

Third-party systems we don't control are out of scope. So are physical attacks, social engineering, phishing, ordinary interface bugs, feature requests, unsupported deployments, and best practice observations without a credible security impact.

Don't run denial-of-service testing, noisy scanning, flooding, brute force, or resource exhaustion. You can report an application-layer issue provable with a few requests, just don't exploit it at scale.

Safe harbour

Research done in good faith under this policy is authorised for the purposes of Swedish, EU, US, and equivalent anti-hacking laws. We won't take legal action against you for it, and we'll confirm that it was authorised if a third party challenges it. This protection applies by default and won't be withdrawn retroactively.

It doesn't cover extortion, intentional harm to users, service degradation, or data destruction. If you're not sure whether a test is in scope, ask first.

Testing safely

Test only with accounts, Communities, systems, and data you own or have permission to use. Don't access, change, keep, or delete another person's data. If it happens by accident, stop, don't keep it, and tell us.

Don't message users outside your test, scrape data, evade safeguards in bulk, or trigger real billing, payments, or notifications without asking us first. Use the minimum access needed to prove impact, and delete personal data from your testing once you no longer need it.

What happens after a report

We aim to reply within a few days. Priority depends on demonstrated impact, affected users, exposed data, and exploitability, and the more severe the issue, the faster we move. If we can't reproduce it, we'll ask for more detail before closing the report. When duplicates arrive, the first report that clearly demonstrates the issue gets the credit.

Keep the report private until we've confirmed and fixed the issue, typically up to 90 days. If a fix takes longer, we'll keep you informed and agree a new timeline. We won't ask for indefinite silence. If we publish an advisory, we'll credit you and coordinate timing with you where we can.

Recognition and rewards

Valid reports may earn a Bug Hunter badge and Fluxer Plutonium gift codes, scaled to severity and report quality. Fluxer staff, contractors, and their immediate families aren't eligible.