# Security contact for fitflexpass.com — RFC 9116 # # If you have found a vulnerability, please report it to the address below # before disclosing it publicly. We will acknowledge within 5 business days. # We do not currently run a paid bounty, but we credit reporters who ask to # be credited. Contact: mailto:security@fitflexpass.com Expires: 2027-07-27T00:00:00.000Z Preferred-Languages: en Canonical: https://fitflexpass.com/.well-known/security.txt Policy: https://fitflexpass.com/terms # In scope: fitflexpass.com, api.fitflexpass.com, and the Fit Flex Pass # iOS/Android apps. # # Out of scope, and please do not test these: payment processing internals # (report those to Stripe), denial-of-service or volumetric testing, social # engineering of staff or listed gym owners, and any testing that touches # real member accounts or real gym check-in data you do not own.