If you've found a security issue affecting any FlatNine product or service, we'd like to hear from you. This page describes how to report it and what to expect after you do.
How to report
Email [email protected] with:
- The affected product / domain.
- Steps to reproduce the issue (PoC, screenshots, or a short video are welcome).
- Your assessment of impact (what an attacker could do).
- Any account or test data you used so we can isolate the trace.
Each product also advertises this contact at /.well-known/security.txt on its own domain, per RFC 9116.
What to expect
- Acknowledgement within 3 business days.
- Initial triage within 7 business days, with a severity assessment and an indicative timeline.
- Fix and disclosure coordinated with you; we aim to resolve high-severity issues in days, others within a reasonable window.
- Please do not disclose publicly until we've shipped a fix, or 90 days have passed without progress, whichever comes first.
Scope
In scope: any production system reachable on the public internet that we operate, including the SaaS apps (Treendly, Leadhall, REreferrals, Cart, Leadbrew, Fastland/Fastlien, Lendlinker, Tastebrew, Sponsorbrew, Rentbrew, Affittibari/Napoli/Palermo, MilanoRentals, FattureExpress, Dosiped) and our marketing properties (flatnine.co, flatnine.org, mikerubini.com).
Out of scope:
- Denial-of-service, volumetric, or brute-force attacks.
- Social engineering of staff, contractors, or customers.
- Physical attacks against our infrastructure.
- Findings that require physical access to a victim's unlocked device.
- Reports generated solely by automated scanners with no demonstrated impact.
- Vulnerabilities in third-party services we use unless we can act on them.
- Missing security headers / cookie flags with no demonstrated exploit path.
- Self-XSS, missing rate limits on non-auth endpoints, click-jacking on pages without sensitive actions.
Safe harbor
If you act in good faith, follow this policy, and avoid disrupting our service or accessing data you don't own, we will not pursue legal action against you for your research. We can't waive third-party rights, so please stay within the scope above.
Credit
We're happy to credit you publicly once an issue is resolved — let us know how you'd like to be named (or whether you'd prefer to stay anonymous).
Last updated 5 September 2026