Reporting a security issue
We take the security of Digital Poster seriously. If you have found a vulnerability in the poster, the app, or our backend, please tell us before disclosing it publicly.
How to report
Email security@flarepointlabs.com with enough detail to reproduce the issue. A proof of concept helps. Please do not run tests that could affect other customers' devices or our service.
What to expect
We will acknowledge your report, keep you updated as we investigate, and let you know when a fix ships. We do not currently run a paid bounty, but we are glad to credit researchers who report in good faith and give us reasonable time to fix an issue before disclosing it.
Scope
The Digital Poster device firmware, the iOS and Android apps, and the api.flarepointlabs.com backend. Reports about third-party services we build on (for example YouTube or TMDB) should go to those providers.
Machine-readable contact details are at /.well-known/security.txt.