Skip to content

Security: Financialstream/financialstream.github.io

Security

SECURITY.md

Security Policy

Scope

This policy covers security issues affecting the public Financial Stream LLC website and its repository infrastructure.

Do not use public GitHub channels for sensitive data

Do not publish any of the following in GitHub Issues, pull requests, discussions, commits, or comments:

  • tax returns or tax identifiers;
  • Social Security numbers or employer identification numbers;
  • bank, payment, payroll, or financial account data;
  • client names paired with confidential financial information;
  • identity documents;
  • passwords, API keys, tokens, webhook secrets, or recovery codes;
  • private correspondence or unredacted screenshots;
  • home addresses or other non-public personal information.

GitHub is not a Financial Stream client portal.

Reporting a website security concern

Do not open a public issue for a suspected vulnerability.

Use the official Financial Stream contact route and clearly identify the message as a website security report:

https://financialstreamllc.com/contact/#structured-request

Include only the minimum information needed to identify the issue. Do not attach or transmit real client data as proof.

A useful report should contain:

  • the affected public URL;
  • the observed behavior;
  • safe reproduction steps;
  • browser or environment details where relevant;
  • the potential impact;
  • a non-sensitive screenshot if needed.

Supported project state

Security review is focused on the current production site and current main branch. Old commits, inactive experiments, and external third-party services may have separate support or disclosure processes.

Responsible handling

Do not:

  • access or modify data that does not belong to you;
  • attempt to obtain client financial information;
  • degrade service availability;
  • send spam or high-volume automated requests;
  • publicly disclose an unresolved issue before reasonable review;
  • use a security report to demand payment or threaten disclosure.

Third-party services

Issues involving GitHub, domain providers, form processors, analytics services, embedded assistants, or other third-party platforms may need to be reported directly to the relevant provider.

Financial Stream cannot guarantee remediation timelines for systems it does not control.

There aren't any published security advisories