Draft public policy; no monetary bounty is promised
Vulnerability disclosure
How security researchers can report StudioFlow vulnerabilities safely and in good faith.
Last updated 21 August 2026
How to report
Email hello@studioflow.business with the subject “StudioFlow security report”. Include the affected URL or feature, reproduction steps, likely impact, supporting evidence and a safe contact method. Do not include more personal data than necessary.
Safe research
- Use only accounts and workspaces you own or have explicit permission to test, and stop if you access another person's data.
- Do not conduct denial of service, social engineering, destructive testing, high-volume scanning, credential stuffing, spam, payment fraud or premature public disclosure.
- The production StudioFlow application and APIs controlled by Code Studios are in scope; third-party services and customer mail servers generally are not.
Response
Code Studios aims to acknowledge credible reports within three business days and coordinate remediation. This is a goal, not a contractual SLA. We do not intend to pursue legal action against good-faith researchers who follow this policy, avoid harm and comply with law.
Questions about this document may be sent to hello@studioflow.business. Draft contractual and privacy materials require formal approval before reliance.