Skip to content

Security: mrzangivand/fli.so

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Found a security issue in fli.so? Let's fix it ASAP:

  1. DO NOT disclose publicly
  2. Email [email protected] with:
    • What's broken
    • How to reproduce
    • Potential impact
    • Fix ideas (if you have any)

Response Timeline

  • 2 hours: Initial response
  • 24 hours: Assessment & action plan
  • 48 hours: Fix implementation target

We're a startup - we move fast on security issues.

Scope

✅ In Scope:

  • fli.so web app
  • API endpoints
  • Auth systems
  • URL shortening
  • PocketBase instance
  • Data handling

❌ Out of Scope:

  • Third-party services
  • Physical access required
  • Social engineering
  • DOS/DDOS
  • Automated scanner results

Security Measures

  • HTTPS everywhere
  • Input validation
  • XSS protection
  • CSRF protection
  • Rate limiting
  • Data encryption
  • Secure sessions

Versions

Latest version only - we move fast.

Recognition

We'll credit security researchers who help us (with permission).


Questions? [email protected]

There aren’t any published security advisories