Last updated
Reporting a vulnerability
If you have found a security vulnerability in a TechRevati website, product or the software we deliver, please tell us. We read every report.
Last updated: 2026-10-06
How to report
Write to security@techrevati.com. Include what is affected (address, endpoint or component, and the version if you know it), steps to reproduce, the impact you observed and how to reach you. Please do not send personal data of third parties you may have seen — describe it instead.
What happens next
We confirm receipt within five working days. We assess the report, tell you whether we could reproduce it and keep you informed until it is fixed. Confirmed vulnerabilities take priority. If you wish, we credit you in the release notes once the fix is out.
Coordinated disclosure
Please give us time to fix before you publish: we ask for 90 days from your report, or less once a fix is available. We agree the publication date with you. We do not run a paid bug bounty programme.
Please
Test only against your own account or data you are allowed to access; do not access, change or delete other people's data, recordings or images; no denial of service, spam or social engineering; once you have shown the problem, stop and report it.
Statutory reporting
TechRevati also reports an actively exploited vulnerability in its products, as the Cyber Resilience Act (Regulation (EU) 2024/2847, Article 14) requires, to the national CSIRT and to ENISA.
Machine-readable contact
This channel is also published at techrevati.com/.well-known/security.txt (RFC 9116). General contact: hello@techrevati.com.
Good-faith Security Research / Safe Harbor
TechRevati considers security research conducted in good faith and in accordance with this policy to be authorised with respect to systems and product instances that TechRevati owns or is legally entitled to authorise for testing.
TechRevati will not bring a civil claim or voluntarily request criminal prosecution solely on the basis of security research that complies with this policy.
This assurance does not authorise access to systems, accounts, devices or data belonging to customers or other third parties and does not bind public authorities or third parties.
Researchers must not intentionally access, copy, alter, retain or disclose third-party personal, confidential or proprietary data beyond what is strictly necessary to demonstrate a vulnerability; disrupt or degrade a service; use social engineering, physical attacks, extortion or persistence; or continue testing after TechRevati asks them to stop.
If third-party or personal data is encountered unintentionally, the researcher must stop accessing that data, minimise any copies, notify TechRevati promptly and follow reasonable instructions for secure deletion.
Researchers should provide sufficient information for TechRevati to reproduce the issue and allow a reasonable opportunity to investigate and remediate it before public disclosure.
Nothing in this policy prevents or excuses reporting or disclosure required by applicable law.
Have a project in mind?
Tell us what you want to build. We respond within one business day.
Built by an EU-incorporated senior team — 20+ years in enterprise delivery.