Vulnerability Disclosure Policy
Last updated: July 26, 2026
Brain-Based Workplace, LLC — https://myflowstate.ai
Our commitment
We take the security of Flow State and our users' data seriously. We welcome reports from security researchers and members of the public who identify potential vulnerabilities, and we are committed to working with you to verify, reproduce, and resolve valid issues. This policy explains how to report a vulnerability, what you can expect from us, and the boundaries of good-faith research.
Scope
In scope
- The Flow State web application at https://myflowstate.ai (and its subdomains).
- The Flow State desktop application (
flowstate-desktop).
Out of scope
- Third-party services we rely on (e.g. Vercel, Supabase, Anthropic, Google, PostHog, Sentry, Resend). Report those to the respective provider.
- Social engineering of the founder, our users, or our vendors (phishing, vishing, etc.).