Responsible Vulnerability Disclosure Program
Mouseflow is committed to maintaining the security and integrity of its systems, services, and customer data. We recognize the value of responsible security research and the important role that independent researchers play in identifying potential weaknesses. This voluntary disclosure program is intended to foster a safe, transparent, and cooperative environment for reporting vulnerabilities in good faith, and Mouseflow commits to reviewing and addressing valid reports in a timely manner.
While Mouseflow does not offer financial rewards or bug bounties, we offer our sincere gratitude to individuals who help improve our security posture through responsible disclosure, and a commitment to address valid issues promptly.
Responsible research and reporting of security and privacy vulnerabilities
If you identify a security weakness or any significant privacy concern affecting Mouseflow’s services, please submit a comprehensive report of the issue to security@mouseflow.com for review.
Individuals reporting potential security vulnerabilities must act in good faith and in a manner that minimizes risk to users and services. In particular, you are required to:
- Make every reasonable effort to avoid privacy violations, service degradation, disruption of production environments, and any destruction, alteration, or unauthorized access to data.
- Refrain from disclosing the vulnerability or any related information to third parties, whether in full or in part, without prior written authorization.
- Submit a clear and comprehensive written report describing the issue, including detailed steps to reproduce the vulnerability. Supporting materials, such as screenshots or non destructive proof of concept code, should be included where necessary to demonstrate the findings.
- Submit a single report per unique vulnerability, even if the issue is encountered multiple times.
- Mouseflow will assess, investigate, and remediate the reported issue within reasonable time.
Scope of the Program
Systems listed in this section are authorized for security testing under this program, provided all other requirements are followed:
- Mouseflow-owned domains and subdomains
- Public-facing web applications and APIs operated by Mouseflow
- Official mobile applications published by Mouseflow
- Infrastructure directly controlled by Mouseflow
Out of Scope
Systems listed in this section are not authorized for testing under this program:
- Third-party services, vendors, integrations, plugins, or platforms
- Cloud provider infrastructure (e.g. GCP, CDN providers)
- Customer websites using Mouseflow scripts
- Customer accounts or customer-configured environments
- Internal corporate IT systems (HR, finance, email systems)
- Employee devices
- Any system not expressly listed as in scope
Prohibited
Activities listed in this section are strictly prohibited, even when performed against in-scope systems.
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) testing
- Stress testing or resource exhaustion attacks
- Social engineering (phishing, vishing, impersonation)
- Physical intrusion attempts
- Bulk data exfiltration
- Accessing, modifying, deleting, or corrupting customer data
- Establishing persistence mechanisms or backdoors
- Automated high-volume scanning that degrades performance or generates low-quality reports
- Testing that degrades user experience or production stability
- Public disclosure without prior written authorization by Mouseflow
If uncertain whether a system is in scope, contact security@mouseflow.com before testing.