The short version
- Found a vulnerability in Flits? Report it to info@nafite.com.
- Don't exploit it, don't look further than necessary and don't share it until it's fixed.
- We'll respond within 3 working days, fix it and keep you posted.
- If you follow these rules, we won't report you to the police.
- If you like, we'll credit you by name. A reward is possible, depending on severity.
1. Why this policy?
Guests and venues trust us with their data. Despite our care, a weakness may slip through. If you find one, we want to hear about it as soon as possible so we can fix it. This policy follows the Coordinated Vulnerability Disclosure approach.
2. How to report
Email info@nafite.com with:
- a description of the vulnerability and where it is (URL, app screen, API endpoint);
- steps to reproduce it, and screenshots or a proof of concept if available;
- your contact details so we can reach you. You may report anonymously, but then we can't keep you updated.
These contact details are also in https://joinflits.com/.well-known/security.txt.
3. What we ask of you
- Don't exploit the vulnerability. Do no more than needed to demonstrate the issue.
- Don't download, view, modify or delete other people's data, and never more than strictly necessary. If you come across personal data, stop and tell us straight away.
- Use only your own accounts. Don't make real claims or orders at venues and don't sign up fake venues: there are real guests and business owners behind them.
- No denial of service, spam or large-scale automated scans that disrupt the service.
- No social engineering (such as phishing our staff, venues or guests) and no physical attacks on offices, venues or equipment.
- Don't install malware or backdoors and don't change other people's settings.
- Don't share the vulnerability with anyone until it is fixed. Disclosure is by agreement; as a guideline, 90 days after your report.
- Delete any data obtained during your research once you've reported it.
4. What we promise
- We'll acknowledge your report within 3 working days, then give an initial assessment and an expected time to fix.
- We'll keep you updated and fix the vulnerability as quickly as possible.
- We treat your report and your details confidentially and use your personal data only to handle your report. We won't share them without your consent unless required by law.
- If you comply with section 3, we will not report you to the police or take legal action against you.
- Recognition: if you wish, we'll thank you by name on this page once the issue is fixed. Depending on severity and report quality, we may also offer a reward. This is at our discretion; there is no entitlement to a reward.
5. Scope
In scope:
- the Flits iOS app (guest mode and venue mode);
- the website joinflits.com and its subdomains;
- Flits's APIs used by the app and website.
Out of scope:
- third-party services we use, such as Stripe (payments), Vercel, SendGrid, Bird, Google Maps and Apple. Please report vulnerabilities in those to the provider directly;
- Supabase's own infrastructure (report to Supabase). A flaw in how Flits has configured Supabase, such as access rights to our data, is in scope;
- reports without a demonstrable security impact, such as missing best-practice headers, version disclosure or automated scanner output without a worked exploitation scenario;
- issues that can only be exploited on a jailbroken or already compromised device.
6. Contact
Security reports: info@nafite.com. Other questions: info@nafite.com.
Nafite B.V. · Spoorstraat 30A, 6511 AH Nijmegen · Chamber of Commerce (KvK) 76060217