Trust centre

Draft public policy; no monetary bounty is promised

Vulnerability disclosure

How security researchers can report StudioFlow vulnerabilities safely and in good faith.

Last updated 21 August 2026

How to report

Email hello@studioflow.business with the subject “StudioFlow security report”. Include the affected URL or feature, reproduction steps, likely impact, supporting evidence and a safe contact method. Do not include more personal data than necessary.

Safe research

  • Use only accounts and workspaces you own or have explicit permission to test, and stop if you access another person's data.
  • Do not conduct denial of service, social engineering, destructive testing, high-volume scanning, credential stuffing, spam, payment fraud or premature public disclosure.
  • The production StudioFlow application and APIs controlled by Code Studios are in scope; third-party services and customer mail servers generally are not.

Response

Code Studios aims to acknowledge credible reports within three business days and coordinate remediation. This is a goal, not a contractual SLA. We do not intend to pursue legal action against good-faith researchers who follow this policy, avoid harm and comply with law.

Questions about this document may be sent to hello@studioflow.business. Draft contractual and privacy materials require formal approval before reliance.