1. Safe harbor
If you follow this program in good faith, we will not pursue legal action for accidental, limited and non-destructive research performed to identify a genuine vulnerability.
Security
We welcome responsible security research that helps us protect RevyAI and our users.
Report real security issues through the approved channel before publishing anything publicly.
Do not disrupt service, access other users data or automate destructive testing.
We do not promise rewards, but we do aim to respond quickly and in good faith.
If you follow this program in good faith, we will not pursue legal action for accidental, limited and non-destructive research performed to identify a genuine vulnerability.
In-scope targets include RevyAI web properties and related infrastructure where a security issue has a meaningful impact on our platform or users.
Please use manual or semi-manual testing only, avoid denial-of-service, avoid credential attacks, and stop immediately if you encounter data that does not belong to you.
Noise-only reports, best-practice suggestions, missing headers without impact, and issues introduced by the reporter are out of scope.
Email the details to security@revyai.io with the target, impact, reproduction steps and any helpful proof-of-concept material.