Responsible disclosure

Report a potential vulnerability

If you believe a security issue affects Flight Outlier, report it privately to RFL LLC so it can be assessed without increasing risk to members or third parties.

Coordinated reporting routeLast updated August 14, 2026

1. How to report

Email ryan@flightoutlier.com with the subject “Security report.” Include, when available:

Do not place a password, one-time sign-in code, private key, full session token, payment credential, passport, or another person’s personal information in ordinary email. If more sensitive evidence is needed, ask for an appropriate transfer method first.

2. Scope

This reporting route covers the Flight Outlier website and member application at flightoutlier.com and the Flight Outlier-operated API used by those surfaces. It does not authorize testing of an airline, loyalty program, booking provider, email provider, AI provider, cloud platform, affiliate partner, or any other third-party system.

3. Use care and minimize harm

Please use only accounts and data you are authorized to use, limit testing to what is reasonably necessary to confirm the issue, and avoid disrupting availability or other people’s use of the service. Do not:

If personal information, credentials, or secrets appear unexpectedly, stop, do not copy or retain more than the minimum needed to identify the issue, and report what happened.

4. What happens next

We will review a report as reasonably practicable, may ask questions, attempt to reproduce the issue, assess its severity and scope, and plan remediation where appropriate. Investigation and remediation time depends on the issue. We do not promise a particular response time, result, public acknowledgment, or disclosure date.

5. No bug bounty or expanded authorization

This is a vulnerability-reporting channel, not a bug-bounty program. No payment, reward, employment, or public credit is offered or promised. This page does not authorize unlawful activity, access to systems or data you do not own or control, violation of third-party terms, or conduct prohibited by the Terms of Service.

6. Machine-readable contact

The current RFC 9116 contact record is available at /.well-known/security.txt. Its expiration date is a maintenance control; use this page or the Contact page if the record appears stale.

7. Security contact

ryan@flightoutlier.com with the subject “Security report.” For immediate danger or a non-Flight Outlier emergency, contact the appropriate emergency service or third-party provider.