# Security and responsible disclosure

**Last updated: 1 October 2026**

We take the security of LogiKFlow and our users' code seriously. For how the Service protects data (encryption, permissions, cookies), see [Security and privacy](/docs/security) in the docs.

## Reporting a vulnerability

Email **security@logikflow.dev** with:

- a description of the issue and its impact;
- steps to reproduce it, or a proof of concept;
- any accounts, repositories or URLs involved.

We'll acknowledge your report within 3 business days, keep you updated, and credit you when it's fixed, if you'd like.

## Guidelines

Please:

- test only against your own accounts and repositories;
- don't access, change or delete other people's data. If you reach any by accident, stop and tell us;
- don't degrade the Service: no denial-of-service, spam or large-scale automated testing;
- give us reasonable time to fix the issue before disclosing it.

We won't take legal action against good-faith research that follows these guidelines.

## Out of scope

- Missing security headers without a demonstrated impact.
- Reports generated only by automated scanners.
- Social engineering, or physical attacks.
- Vulnerabilities in GitHub, Cloudflare or AI agents themselves. Report those to the vendor.

A machine-readable contact is at [/.well-known/security.txt](/.well-known/security.txt).

LogiKFlow is operated by ZikkLabs, Kerala, India.
