Vulnerability disclosure
Help us protect the people and businesses who use RVITYLIZE services. Please report suspected security vulnerabilities privately so we can investigate responsibly.
Reporting a vulnerability
Send security reports to rvitylizesecurity@gmail.com.
Where practical, include:
- The affected URL or service.
- A description of the vulnerability.
- Steps to reproduce the issue.
- The potential impact.
- The minimum evidence necessary to demonstrate the issue.
Keep reports private and avoid including unnecessary personal, private, or client data.
Good-faith testing
Stop once you have sufficient evidence to demonstrate a vulnerability. Keep research non-destructive and limited to the minimum necessary proof.
Please do not:
- Access more private or client data than is minimally necessary to demonstrate the issue.
- Download or retain unnecessary private data.
- Modify or delete data.
- Escalate privileges unnecessarily.
- Establish persistence or install malware.
- Conduct denial-of-service attacks or resource exhaustion.
- Intentionally disrupt service.
- Perform social engineering or phishing.
- Publicly disclose unresolved vulnerabilities before RVITYLIZE has had reasonable time to investigate.
If you accidentally encounter sensitive information, stop and report it instead of exploring further.
Automated security tools and agents
Non-destructive automated discovery, including discovery by scanners and AI security agents, is acceptable only within this policy's scope and when it:
- Uses conservative request rates.
- Does not alter data or system state.
- Does not attempt credential attacks.
- Does not perform denial-of-service behavior.
- Stops further exploitation once sufficient proof exists.
- Does not retrieve extra sensitive records merely to prove severity.
- Does not escalate privileges unnecessarily.
- Reports the minimum necessary evidence to rvitylizesecurity@gmail.com.
If you discover credible evidence of a vulnerability, you do not need to determine how far the access can be extended. Stop at the minimum viable proof and report the finding.
This guidance describes expected research behavior; it is not a technical security control.
No bug-bounty program
RVITYLIZE does not currently operate a bug-bounty program. Reporting a vulnerability does not create an entitlement to payment.
Third-party and client systems
This policy applies to systems RVITYLIZE owns or operates. It does not grant authorization to test third-party platforms or client-controlled systems that RVITYLIZE does not own or operate. Obtain authorization from the relevant owner before testing those systems.
Legal boundary
This policy describes RVITYLIZE's preferred responsible-disclosure process. It does not provide blanket legal safe harbor, override applicable law or other agreements, or waive the rights of RVITYLIZE, its clients, or third parties.
Machine-readable reporting information: security.txt