Security policy & coordinated disclosure
We welcome reports of security vulnerabilities in Reddi (askreddi.com). This page is the policy referenced by our /.well-known/security.txt.
How to report
Email security@askreddi.com with a description of the issue and the steps to reproduce it. Please do not include customer document contents, credentials, or other tenants’ data in your report.
Scope & safe harbour
- Do not access, modify, or exfiltrate data belonging to other firms/tenants while testing.
- Do not run denial-of-service tests, spam, or social-engineering against staff or customers.
- Automated scanning that degrades service availability is out of scope.
- Good-faith research that respects the above will not be pursued by us.
What to expect
We aim to acknowledge reports within two business days and to keep you updated as we investigate. We do not currently operate a paid bug-bounty programme; we are happy to credit reporters here with their permission.
Acknowledgments
Reporters who have responsibly disclosed issues will be listed here with their consent.