Security and vulnerability disclosure

    FlintX builds cybersecurity products for critical infrastructure and operational technology (OT) networks. Our products are designed to run in sensitive environments, so we treat reports of vulnerabilities in our own software and hardware as a priority.

    If you believe you have found a vulnerability in a FlintX product or service, please tell us. This page is our coordinated vulnerability disclosure policy and the single point of contact for vulnerability reports. It explains how to report an issue, what we will do with your report, and how we disclose fixes.

    Email security@flintx.ai

    Report a vulnerability

    Email security@flintx.ai.

    Please include as much of the following as you can:

    • The product and the version or firmware build affected (Forge, Forge Nano, Probe or flintx.ai)
    • A clear description of the vulnerability and its impact
    • Steps to reproduce, or a proof of concept
    • Logs, screenshots or packet captures that help us reproduce it
    • Whether you plan to publish your findings, and when
    • How you would like to be credited, if at all

    If you want to encrypt your report, send a first email with no technical detail asking for a public key or a secure upload link, and we will reply with one.

    If you believe a vulnerability is being actively exploited, start the subject line with URGENT and say so in the first sentence. We prioritize those reports.

    Please report through this address and not through social media or public forums, so that we can handle your report confidentially.

    What to expect

    We run a documented process that follows ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling). These are the steps and the targets we work to.

    1. Acknowledgment. We acknowledge your report within 3 business days.
    2. Verification and assessment. We reproduce the issue and assess its severity, usually within 7 days. We score severity with CVSS.
    3. Updates. We update you at least every 14 days until the issue is resolved, and sooner if something changes.
    4. Fix and coordination. We develop and test a fix or mitigation, then agree a disclosure date with you. Our default coordination window is 90 days from the date of your report. Hardware, firmware and issues that involve other vendors can need longer. We will agree any extension with you in advance.
    5. Advisory and credit. When a fix is available we publish a security advisory, request a CVE ID where applicable, notify affected customers directly, and credit you if you would like.

    Scope

    In scope:

    • Forge and Forge Nano appliances: firmware, operating system, platform software, web interface, APIs and update mechanism
    • Probe collectors: firmware and software
    • flintx.ai and other web services operated by FlintX

    Test only on equipment you own or are authorized to test. If you need an evaluation unit or a test environment, ask us at the address above.

    Out of scope:

    • Any customer environment, and any live industrial control or OT network. Never test against a system you do not own or do not have written permission to test.
    • Denial of service, load testing or stress testing
    • Social engineering, phishing, or physical attacks against FlintX staff, offices or customers
    • Reports from automated scanners with no demonstrated security impact
    • Vulnerabilities in third-party products or open source components, unless they can be exploited through a FlintX product. Please report those to the upstream vendor or maintainer, and tell us as well so we can assess our exposure.

    Ground rules for researchers

    • Make a good faith effort to avoid privacy violations, data destruction and disruption of services.
    • Access only as much data as you need to demonstrate the issue. If you come across customer data or credentials, stop and tell us straight away. Do not copy, keep or share them.
    • Do not modify or delete data, pivot to other systems, or keep access once you have shown the issue.
    • Keep the details confidential until we have agreed a disclosure date with you.

    Safe harbor

    If you act in good faith and follow this policy, we will not take legal action against you and we will not report you to law enforcement for your research. If a third party takes legal action against you for research that followed this policy, we will say that it was carried out under this policy.

    This applies to FlintX products and systems only. It does not extend to customer systems or other companies' systems, and it cannot bind third parties or public authorities.

    Recognition

    We credit researchers by name, or anonymously if you prefer, in the advisory for the issue you reported. We do not currently run a paid bounty program.

    Security advisories

    When we fix a vulnerability in a FlintX product, we publish an advisory on this page. Each advisory lists the affected products and versions, the severity and CVSS vector, the impact, and the steps to fix or mitigate the issue. If a CVE ID has been assigned, it is included.

    Standards

    FlintX operates this process in line with ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling processes). Reports are handled by FlintX engineering and tracked from receipt through to release and disclosure.

    Contact

    Vulnerability reports: security@flintx.ai

    For anything that is not a vulnerability report, use our contact page.

    Last updated: October 2026