security

Responsible Disclosure

Security researchers can report suspected vulnerabilities in Reconify systems through this coordinated disclosure process.

Effective June 20, 2026 · Last updated June 20, 2026

1. How to report a vulnerability

Send suspected security vulnerabilities to kolawole@reconifyhq.com. Please avoid sending customer data, secrets, or exploit code beyond what is needed to understand the issue.

2. What to include

A useful report gives us enough detail to reproduce and assess the issue. Include the following information when available:

  • The affected domain, endpoint, package, or feature.
  • The vulnerability type and likely impact.
  • Clear reproduction steps and any relevant request IDs.
  • Screenshots, logs, or proof-of-concept details that do not expose customer data or secrets.
  • Your contact information for follow-up questions.

3. Research boundaries

Good-faith testing must avoid harm to Reconify, customers, and production systems. Do not access, modify, delete, export, or disclose data that does not belong to you. Do not run denial of service tests, phishing, social engineering, physical attacks, spam, destructive testing, or broad automated scanning without written authorization.

4. What happens next

We will confirm receipt and share a triage status as soon as practical. After triage, we will tell you whether the issue is accepted, out of scope, a duplicate, or not reproducible. Remediation and disclosure timing depends on the issue’s risk, complexity, and affected systems.

5. Coordinated disclosure

Please give us a reasonable opportunity to investigate and fix the issue before public disclosure. We will work with you on a disclosure timeline when a report is valid and affects Reconify customers, infrastructure, or open-source users.

6. Good-faith research

Reconify does not intend to pursue legal action against researchers who act in good faith, follow this policy, avoid privacy violations, avoid service disruption, and report vulnerabilities promptly. This statement does not authorize activity that violates applicable law or third-party rights.