generated: '2026-09-17' method: searched source: https://github.com/Flagsmith/flagsmith/security/policy policy_url: https://github.com/Flagsmith/flagsmith/security/policy raw_url: https://raw.githubusercontent.com/Flagsmith/flagsmith/main/SECURITY.md evidence: - {url: 'https://raw.githubusercontent.com/Flagsmith/flagsmith/main/SECURITY.md', status: 200} - {url: 'https://github.com/Flagsmith/flagsmith/security/policy', status: 200} - {url: 'https://flagsmith.com/.well-known/security.txt', status: 404} - {url: 'https://api.flagsmith.com/.well-known/security.txt', status: 404} - {url: 'https://docs.flagsmith.com/.well-known/security.txt', status: 404} checked: '2026-09-17' published: true contact: email: support@flagsmith.com note: >- Written in the policy as "support[at]flagsmith[dot]com" (obfuscated against scrapers). There is no dedicated security@ address and no PGP key. security_txt: false bug_bounty: program: false platform: null note: No HackerOne, Bugcrowd or Intigriti programme was found. safe_harbor: false disclosure_policy: stated_process: - Assess the risk - Identify the remediation - Implement and deploy a fix to the SaaS platform, Docker images and source code - Create a GitHub issue labelled `Security` where appropriate response_sla: null scope: null note: >- Short, real, and honest about what it is: a process commitment for the open-source project and the SaaS platform, not a formal VDP. No acknowledgement window, no severity SLA, no defined scope, no safe-harbour language, and no coordinated-disclosure timeline. Everything it does say, though, it says plainly — including that a fix lands in the Docker images and source, which matters to the large self-hosted population this product has. gap: >- The policy is discoverable only from the GitHub repository. A /.well-known/security.txt on flagsmith.com pointing at it would cost one file and is the single cheapest security-posture improvement available here; all six hosts probed return 404.