Last updated: August 11, 2026
If you believe you have found a security vulnerability in AcqFlo, please email security@acqflo.com with the subject line “Security: [brief description].” We acknowledge reports promptly and prioritize confirmed issues by severity.
Please include enough detail to reproduce the issue: a description of the vulnerability, the affected URL or endpoint, steps to reproduce, and the impact you observed. If you have a proof-of-concept, attach it.
AcqFlo runs on infrastructure certified to SOC 2 Type II (Supabase, Vercel). AcqFlo is not itself SOC 2 certified. Our current controls include:
If you are evaluating AcqFlo on behalf of your organization, we maintain a written vendor security assessment covering tenant isolation, data residency, our full subprocessor list, encryption, retention and deletion, incident response and breach-notification timelines, business continuity, and a candid accounting of the controls we do not yet have. It answers most standard questionnaires directly. Email security@acqflo.com and we will send it, along with our incident response plan.
We would rather answer these questions once, in writing and up front, than discover a blocker late in your review.
The following are in scope:
acqflo.comThe following are out of scope:
We will not pursue legal action against researchers who report vulnerabilities in good faith and follow this policy. Specifically, we ask that you:
We aim to acknowledge reports within 2 business days, triage within 5 business days, and resolve critical or high-severity issues within 30 days. We will keep you informed of progress and notify you when the issue is resolved. We support coordinated disclosure and welcome public write-ups once a fix is released.
AcqFlo does not currently operate a paid bug bounty program. With your permission, we are happy to acknowledge your contribution publicly when a fix is released.
Our security.txt file follows RFC 9116.