Flashcards Open Source App is a monorepo for the hosted backend, web app, iOS app, Android app, MCP connector, Agent API, database migrations, and deployment code. Use this policy for vulnerabilities in any part of the product or repository.
Report vulnerabilities privately by emailing security@flashcards-open-source-app.com.
If email is unavailable, use the support page at
https://flashcards-open-source-app.com/support/ and mark the message as a
security report.
Please include:
- The affected component, route, app, package, or infrastructure area.
- Reproduction steps, proof-of-concept input, and expected versus actual behavior.
- Impact, including what data or accounts could be affected.
- Relevant request ids, timestamps, versions, commits, logs, screenshots, or error responses.
- Your preferred contact information for follow-up.
Do not access data that is not yours, modify other users' data, or perform testing that could interrupt the hosted service.
Please do not disclose a vulnerability publicly until we have coordinated a fix, release, and disclosure timing. We will acknowledge reports, investigate the affected product surfaces, and coordinate remediation details directly with the reporter.