# Security policy Do not report a vulnerability in a pull request, on feedback.fluxer.com, in a Fluxer community, or in a direct message to staff. Submit a report through or email . Include the affected component, impact, reproduction steps, and supporting evidence. Remove unrelated personal data and secrets. The programme scope, testing rules, safe harbour, disclosure process, and reward terms are published at . That page is authoritative.