Security at Rekaz

Report a security vulnerability

If you encounter a potential security vulnerability while using a Rekaz service, or during testing you are otherwise authorized to perform, please report it to us by email.

Email a security report security@rekaz.io

What to report

This reporting channel covers potential vulnerabilities in systems owned and controlled by Rekaz, including:

  • Rekaz-operated websites and subdomains.
  • Rekaz web and mobile applications.
  • Rekaz APIs and platform services.
  • Infrastructure and configurations directly controlled by Rekaz.

What is not covered

Please do not use this channel to test or report issues involving:

  • Customer-owned systems, third-party services, or assets not controlled by Rekaz.
  • Social engineering, phishing, physical intrusion, or attempts against Rekaz staff or customers.
  • Denial-of-service, resource exhaustion, or any activity that degrades availability.
  • High-volume automated scanning, spam, or disruptive traffic.

What to include

A clear, focused report helps us understand and investigate the issue. Please include:

  • The affected URL, application, API, or other asset.
  • Concise steps to reproduce the behavior.
  • The potential security impact and who could be affected.
  • Non-sensitive screenshots, request details, or logs that demonstrate the issue.
  • Your preferred contact details for any necessary follow-up.

Protect people and services

When investigating or documenting a suspected issue, please:

  • Do not disrupt services, degrade performance, or affect other users.
  • Do not access, copy, modify, download, or delete data beyond what is strictly necessary to describe the issue.
  • Stop testing and report immediately if you encounter personal, financial, or other sensitive data.
  • Avoid public disclosure while Rekaz has a reasonable opportunity to investigate the report.

What to expect

We review reports based on their impact, clarity, and completeness. We do not promise a specific acknowledgement or resolution timeframe.

This reporting channel is not a bug-bounty program, and Rekaz does not offer financial rewards for submissions.

This page provides a way to report potential vulnerabilities. It does not grant authorization to access or test any system.