generated: '2026-07-19' method: searched probe: true source: https://www.flint.com/security/vdp policy: - https://www.flint.com/security/vdp contact: - mailto:security@tryflint.com encryption: https://tryflint.com/pgp-key.asc bug_bounty: false disclosure_window_days: 90 safe_harbor: true scope: Any digital assets owned, operated, or maintained by Flint Technologies Inc. researcher_obligations: - Report vulnerabilities promptly. - Provide at least 90 days before public disclosure. - Limit data access to the minimum needed to demonstrate a proof of concept. - Stop immediately upon encountering user data (PII, PHI, credit card data). - Use only official channels for communication. evidence: - source: well-known/flint-security.txt kind: security.txt - source: https://www.flint.com/security/vdp kind: disclosure-policy