1. Introduction
Flex Online (Pty) Ltd ("Flex", "we", "our" or "us") is committed to maintaining the security, integrity and availability of the Flex Platform.
We recognise that security researchers, Customers and Platform Users may identify vulnerabilities that could affect the security of the Flex Platform or related services.
This Vulnerability Disclosure Policy explains how such vulnerabilities should be reported and how Flex will respond to responsible disclosures.
We value good-faith security research and encourage responsible reporting that helps us improve the security of the Flex Platform.
2. Scope
This Policy applies to suspected security vulnerabilities affecting:
- the Flex Platform;
- the Flex Website;
- publicly accessible APIs operated by Flex;
- infrastructure directly managed by Flex; and
- other publicly accessible systems operated by Flex.
This Policy does not apply to:
- third-party systems not operated by Flex;
- Customer-managed infrastructure;
- Customer-developed integrations;
- vulnerabilities in third-party software unrelated to Flex; or
- issues that do not present a genuine security risk.
3. Good Faith Research
Flex supports legitimate security research conducted in good faith.
We consider research to be conducted in good faith where the individual:
- acts with the intention of improving security;
- avoids unnecessary disruption to services;
- respects the privacy of Platform Users and Customers;
- reports findings responsibly;
- allows Flex a reasonable opportunity to investigate and remediate the issue before public disclosure; and
- complies with applicable laws.
4. Expected Conduct
When investigating a potential vulnerability, we ask that researchers:
- minimise any impact on the availability of the Flex Platform;
- access only the information reasonably necessary to demonstrate the vulnerability;
- avoid modifying or deleting Customer Content;
- avoid viewing Personal Information unless absolutely unavoidable;
- immediately cease testing if Customer data could be compromised;
- report the issue as soon as reasonably practicable; and
- cooperate with Flex during the investigation where appropriate.
5. Prohibited Activities
This Policy does not authorise activities that are unlawful or that create unnecessary risk.
Researchers must not intentionally:
- access Customer accounts without authorisation;
- access Customer Content beyond what is reasonably necessary to demonstrate a vulnerability;
- modify or destroy information;
- disrupt platform availability;
- conduct denial-of-service attacks;
- deploy malware;
- use social engineering against Customers, Platform Users or Flex personnel;
- physically access Flex facilities without authorisation;
- exploit vulnerabilities for personal benefit;
- publicly disclose a vulnerability before Flex has had a reasonable opportunity to investigate and address it; or
- attempt to extort Flex or its Customers.
6. How to Report a Vulnerability
Reports should include as much relevant information as reasonably possible, including:
- a description of the vulnerability;
- the affected service or functionality;
- the date and time the issue was identified;
- steps required to reproduce the issue;
- proof-of-concept information where appropriate;
- the potential security impact;
- screenshots or supporting evidence where available; and
- your contact information should we require clarification.
Reports should be submitted to:
Email: trust@flexonline.io
7. Our Response
Upon receiving a vulnerability report, Flex will seek to:
- acknowledge receipt within a reasonable period;
- assess the reported issue;
- determine the severity and potential impact;
- investigate the vulnerability;
- implement appropriate remediation where necessary;
- communicate with the reporter where appropriate; and
- close the matter once the investigation has been completed.
Not every reported issue will constitute a security vulnerability.
8. Coordinated Disclosure
Flex believes vulnerabilities should be disclosed responsibly.
We respectfully request that researchers:
- allow Flex a reasonable opportunity to investigate;
- avoid public disclosure while remediation is underway;
- coordinate disclosure with Flex where appropriate; and
- avoid releasing exploit details that could place Customers or Platform Users at unnecessary risk.
Where appropriate, Flex may work collaboratively with the reporting individual regarding the timing of any public disclosure.
9. Safe Harbour
Where security research is conducted:
- in good faith;
- in accordance with this Policy;
- without intentionally compromising Customer information;
- without causing unnecessary disruption; and
- in compliance with applicable law,
Flex will not ordinarily pursue legal action solely because of the reported security research.
Nothing in this Policy limits Flex's rights where activities are unlawful, malicious, reckless or exceed the scope of responsible security research.
10. Bug Bounties
At the time of publication, Flex does not operate a public bug bounty programme.
Submission of a vulnerability report does not create any entitlement to financial compensation or other reward.
Flex may, at its sole discretion, acknowledge or recognise responsible disclosures where appropriate.
11. Customer Security
Many Flex environments are dedicated to individual Customers.
Where a reported vulnerability affects a specific Customer environment, Flex may:
- notify the affected Customer where appropriate;
- coordinate investigation with the Customer where required;
- implement remediation in accordance with contractual obligations; and
- comply with applicable legal and privacy requirements.
12. Privacy
Information submitted under this Policy will be processed in accordance with the Privacy Policy.
Flex will use vulnerability reports only for legitimate security, operational and legal purposes.
Where reports contain Personal Information, Flex will process that information in accordance with applicable privacy legislation.
13. Policy Updates
Flex may amend this Policy from time to time to reflect:
- changes to the Flex Platform;
- changes to security practices;
- legal developments;
- operational improvements; or
- evolving industry standards.
The latest version will always be published within the Flex Trust Centre.
14. Related Documents
This Policy should be read together with:
- Security Overview;
- Information Security Policy;
- Privacy Policy;
- Responsible AI Policy;
- Acceptable Use Policy;
- Platform Terms; and
- Website Terms.
15. Contact
Security vulnerabilities should be reported to:
Flex Online (Pty) Ltd
Security Team
Email: trust@flexonline.io
Website: www.flexonline.io