Report a security vulnerability
If you encounter a potential security vulnerability while using a Rekaz service, or during testing you are otherwise authorized to perform, please report it to us by email.
What to report
This reporting channel covers potential vulnerabilities in systems owned and controlled by Rekaz, including:
- Rekaz-operated websites and subdomains.
- Rekaz web and mobile applications.
- Rekaz APIs and platform services.
- Infrastructure and configurations directly controlled by Rekaz.
What is not covered
Please do not use this channel to test or report issues involving:
- Customer-owned systems, third-party services, or assets not controlled by Rekaz.
- Social engineering, phishing, physical intrusion, or attempts against Rekaz staff or customers.
- Denial-of-service, resource exhaustion, or any activity that degrades availability.
- High-volume automated scanning, spam, or disruptive traffic.
What to include
A clear, focused report helps us understand and investigate the issue. Please include:
- The affected URL, application, API, or other asset.
- Concise steps to reproduce the behavior.
- The potential security impact and who could be affected.
- Non-sensitive screenshots, request details, or logs that demonstrate the issue.
- Your preferred contact details for any necessary follow-up.
Protect people and services
When investigating or documenting a suspected issue, please:
- Do not disrupt services, degrade performance, or affect other users.
- Do not access, copy, modify, download, or delete data beyond what is strictly necessary to describe the issue.
- Stop testing and report immediately if you encounter personal, financial, or other sensitive data.
- Avoid public disclosure while Rekaz has a reasonable opportunity to investigate the report.
What to expect
We review reports based on their impact, clarity, and completeness. We do not promise a specific acknowledgement or resolution timeframe.
This reporting channel is not a bug-bounty program, and Rekaz does not offer financial rewards for submissions.
This page provides a way to report potential vulnerabilities. It does not grant authorization to access or test any system.