Vulnerability Disclosure

Report ChargeFlow.Pro security issues responsibly and review our vulnerability disclosure scope, safe testing rules, and contact process.

Where to report

Email support@chargeflow.pro with a clear description, affected URL or endpoint, reproduction steps, and the impact you believe the issue has.

Safe testing

Use your own account and data only. Do not access, modify, delete, or export another user's records, and do not attempt to manipulate ad serving, payment, App Store, or third-party provider accounts.

Out of scope

Do not run denial-of-service tests, spam, social engineering, phishing, physical attacks, ad fraud, click fraud, store review manipulation, or broad automated scans against the production service.

Response process

We will review credible reports, prioritize fixes based on impact, and may contact you for clarification using the email you provide.

No compensation promise

ChargeFlow.Pro does not currently operate a paid bug bounty program, so reports are handled as responsible disclosure without guaranteed rewards.