FloorTest

Draft for the private beta, not yet reviewed by a lawyer. It describes how FloorTest works today and will be replaced by a reviewed version before public launch.

Responsible Disclosure

Last updated 2 October 2026

Report a security problem

If you think you've found a security vulnerability in FloorTest, email info@imullar.com with "Security" in the subject. Include what you found, the steps to reproduce it, and what an attacker could do with it.

Our promise

We'll acknowledge your report within 3 working days, keep you updated, and tell you when it's fixed. If you follow this policy in good faith, we won't take legal action against you for your research, and we'll credit you if you'd like.

Please

Only test against your own accounts. Don't access, change or delete other people's data or music; stop and report as soon as you see any.

Don't run denial-of-service, spam, social-engineering or physical attacks, and don't use automated scanners that send heavy traffic.

Give us reasonable time to fix the problem before telling anyone else.

Out of scope

Missing best-practice headers with no real impact, clickjacking on pages with no sensitive actions, reports from automated tools without a working example, and issues in services we use (report those to the provider).

Rewards

We don't run a paid bug bounty yet.