This policy covers security issues affecting the public Financial Stream LLC website and its repository infrastructure.
Do not publish any of the following in GitHub Issues, pull requests, discussions, commits, or comments:
- tax returns or tax identifiers;
- Social Security numbers or employer identification numbers;
- bank, payment, payroll, or financial account data;
- client names paired with confidential financial information;
- identity documents;
- passwords, API keys, tokens, webhook secrets, or recovery codes;
- private correspondence or unredacted screenshots;
- home addresses or other non-public personal information.
GitHub is not a Financial Stream client portal.
Do not open a public issue for a suspected vulnerability.
Use the official Financial Stream contact route and clearly identify the message as a website security report:
https://financialstreamllc.com/contact/#structured-request
Include only the minimum information needed to identify the issue. Do not attach or transmit real client data as proof.
A useful report should contain:
- the affected public URL;
- the observed behavior;
- safe reproduction steps;
- browser or environment details where relevant;
- the potential impact;
- a non-sensitive screenshot if needed.
Security review is focused on the current production site and current main branch. Old commits, inactive experiments, and external third-party services may have separate support or disclosure processes.
Do not:
- access or modify data that does not belong to you;
- attempt to obtain client financial information;
- degrade service availability;
- send spam or high-volume automated requests;
- publicly disclose an unresolved issue before reasonable review;
- use a security report to demand payment or threaten disclosure.
Issues involving GitHub, domain providers, form processors, analytics services, embedded assistants, or other third-party platforms may need to be reported directly to the relevant provider.
Financial Stream cannot guarantee remediation timelines for systems it does not control.