Responsible disclosure
Report a potential vulnerability
If you believe a security issue affects Flight Outlier, report it privately to RFL LLC so it can be assessed without increasing risk to members or third parties.
1. How to report
Email [email protected] with the subject “Security report.” Include, when available:
- the affected URL, feature, and app version;
- clear reproduction steps and the result you observed;
- the potential impact and whether it appears repeatable;
- the browser, device, account type, and approximate time of testing; and
- the smallest sanitized evidence needed to understand the issue.
Do not place a password, one-time sign-in code, private key, full session token, payment credential, passport, or another person’s personal information in ordinary email. If more sensitive evidence is needed, ask for an appropriate transfer method first.
2. Scope
This reporting route covers the Flight Outlier website and member application at flightoutlier.com and the Flight Outlier-operated API used by those surfaces. It does not authorize testing of an airline, loyalty program, booking provider, email provider, AI provider, cloud platform, affiliate partner, or any other third-party system.
3. Use care and minimize harm
Please use only accounts and data you are authorized to use, limit testing to what is reasonably necessary to confirm the issue, and avoid disrupting availability or other people’s use of the service. Do not:
- access, change, download, retain, or disclose another person’s data or account;
- use denial-of-service, destructive, high-volume, spam, phishing, social-engineering, or physical attacks;
- install malware, persist access, or evade a security control beyond what is necessary to demonstrate the issue; or
- publicly disclose the issue before RFL LLC has had a reasonable opportunity to investigate and coordinate remediation.
If personal information, credentials, or secrets appear unexpectedly, stop, do not copy or retain more than the minimum needed to identify the issue, and report what happened.
4. What happens next
We will review a report as reasonably practicable, may ask questions, attempt to reproduce the issue, assess its severity and scope, and plan remediation where appropriate. Investigation and remediation time depends on the issue. We do not promise a particular response time, result, public acknowledgment, or disclosure date.
5. No bug bounty or expanded authorization
This is a vulnerability-reporting channel, not a bug-bounty program. No payment, reward, employment, or public credit is offered or promised. This page does not authorize unlawful activity, access to systems or data you do not own or control, violation of third-party terms, or conduct prohibited by the Terms of Service.
6. Machine-readable contact
The current RFC 9116 contact record is available at /.well-known/security.txt. Its expiration date is a maintenance control; use this page or the Contact page if the record appears stale.
7. Security contact
[email protected] with the subject “Security report.” For immediate danger or a non-Flight Outlier emergency, contact the appropriate emergency service or third-party provider.