Security and responsible disclosure
Reporting a vulnerability
If you believe you have found a security vulnerability in CashflowReviewer, report it to us privately before disclosing it anywhere else. Use the contact form and begin your message with SECURITY; it reaches the platform owner directly and is triaged ahead of sales enquiries. Include the steps to reproduce, the affected URL, and the time of your test.
What is out of scope
Please do not test against accounts you do not own, use real bank statements or customer data, run automated scanning that degrades the service, or attempt denial of service.
Our commitment
Testing that respects those limits, is reported privately, and gives us reasonable time to fix the issue will not lead to legal action from us.
This page is the policy that /.well-known/security.txt points at. Machine-readable contact details, in the RFC 9116 format, are published there.
Everything else
Section 6 of the Terms of Service governs acceptable use, and Section 8 explains the limits of what any information system can guarantee. Nothing on this page changes those Terms.