Floom holds portfolio data for venture and private equity funds. If you have found a weakness in our systems, we want to hear about it — and we will not take action against you for telling us.
Email us with enough detail to reproduce the issue — the affected endpoint or page, the steps you took, and what you observed. Screenshots or a short recording help.
security@floom.vc →We acknowledge reports within 2 business days and tell you our assessment of severity within 5 business days. We will keep you updated until it is resolved, and we will tell you when the fix ships.
If you act in good faith under the guidance below, we will not pursue legal action, and we will not report you. Tell us before disclosing publicly and give us reasonable time to fix it.
Please do: test only against accounts you own or have permission to use; stop as soon as you have confirmed a vulnerability exists; and give us reasonable time to fix an issue before disclosing it.
Please do not: access, modify, download or retain data belonging to anyone else; run automated scanning that degrades service for our customers; attempt denial of service; use social engineering or physical attacks against our staff or providers; or hold a finding for payment.
Anything that lets one customer reach another customer’s data, any path to authentication bypass or privilege escalation, exposure of credentials or API keys, remote code execution, and anything that would let portfolio data leave our systems.
Findings from automated scanners without a demonstrated impact, missing security headers with no exploitable consequence, rate limiting on non-authentication endpoints, reports about software versions alone, and issues on third-party services we do not operate — report those to the provider.
We aim to remediate critical issues within 7 days and high-severity issues within 30 days of confirming them. We are happy to credit you once a fix has shipped, if you would like that.
Looking for our compliance posture rather than a place to report a bug? Our Trust Center covers SOC 2 status, the controls we operate, where your data is held, and the documents we share on request.
This policy is also published in machine-readable form at /.well-known/security.txt. If you cannot reach the security address, support@floom.vc also reaches us.