Legal
Our policy for reporting security vulnerabilities and receiving discretionary bug bounties.
Effective Date: June 13, 2026 — Last Updated: June 13, 2026
We Welcome Security Research
We encourage responsible security research on our products and services. If you discover a vulnerability, please report it to us following this policy. We commit to working with researchers to resolve issues responsibly.
Email security@revyrlabs.com
Use PGP encryption for sensitive reports. Request our public key by replying to that address.
Include details
Describe the vulnerability, steps to reproduce, potential impact, and suggested fix.
Provide proof of concept
Include screenshots, code snippets, or a minimal reproduction case if possible.
Act in Good Faith
Report vulnerabilities responsibly without exploiting them or accessing data beyond what's necessary for testing.
Don't Access User Data
Never access, modify, or delete user data. If you encounter user data during testing, stop and report immediately.
Give Us Time to Respond
Allow us reasonable time to fix the vulnerability before disclosing it publicly.
No Automated Scanning
Don't run automated vulnerability scanners or tools that could impact service availability.
Response Within 48 Hours
We'll acknowledge receipt of your report within 48 hours and provide a timeline for remediation.
Regular Updates
We'll keep you updated on our progress and notify you when the issue is resolved.
Credit for Your Work
With your permission, we'll credit you in our changelog and security advisories.
Discretionary Bug Bounty
We may offer a discretionary bounty for valid security findings at our sole discretion. Bounty amounts vary based on severity and impact.
PGP Public Key
For sensitive vulnerability reports, encrypt your message with our PGP public key.
Request PGP key →Questions?
Email security@revyrlabs.com for any questions about this policy.