Security & responsible disclosure

We build a security product, so we hold ourselves to the same standard we check others against. If you've found a vulnerability in Reeve, we want to hear from you.

We welcome good-faith security research and will work with you to understand and fix any valid issue quickly.

How to report a vulnerability

Email us with enough detail to reproduce the issue. Please give us a reasonable chance to fix it before sharing it publicly.

Email the security team

Helpful things to include

  • A clear description of the issue and its impact.
  • Step-by-step instructions or a proof of concept to reproduce it.
  • The URL, page, or endpoint affected.
  • Your name or handle, if you'd like credit.

Scope

Our own websites and services (reeve.page and the Reeve scanner) are in scope. Please don’t test third-party apps through Reeve, run denial-of-service or automated load tests, or access, modify or exfiltrate data that isn’t yours.

Safe harbor

We won’t pursue or support legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service disruption, and give us a reasonable time to respond before disclosure.

What to expect

We'll acknowledge your report, keep you updated as we investigate, and let you know when the issue is resolved. We don't run a paid bounty program yet, but we're genuinely grateful — and happy to credit you.

Machine-readable contact details are published at /.well-known/security.txt. /.well-known/security.txt