Security

Vulnerability Disclosure Program

We welcome responsible security research that helps us protect RevyAI and our users.

Updated: July 4, 2026RevyAI.io

Report real security issues through the approved channel before publishing anything publicly.

Do not disrupt service, access other users data or automate destructive testing.

We do not promise rewards, but we do aim to respond quickly and in good faith.

1. Safe harbor

If you follow this program in good faith, we will not pursue legal action for accidental, limited and non-destructive research performed to identify a genuine vulnerability.

2. Scope

In-scope targets include RevyAI web properties and related infrastructure where a security issue has a meaningful impact on our platform or users.

3. Rules of engagement

Please use manual or semi-manual testing only, avoid denial-of-service, avoid credential attacks, and stop immediately if you encounter data that does not belong to you.

4. Out of scope

Noise-only reports, best-practice suggestions, missing headers without impact, and issues introduced by the reporter are out of scope.

5. How to report

Email the details to security@revyai.io with the target, impact, reproduction steps and any helpful proof-of-concept material.