Security
Vulnerability disclosure policy
We welcome reports from security researchers who find a vulnerability in Renevo. Email it to [email protected], one issue per email, and follow the rules on this page while you test.
Scope
In scope
-
renevo.io, this website -
portal.renevo.io, the web app, including everything under/api - The Renevo iOS app, latest App Store version. It is not on the App Store yet, and comes into scope when it is released.
Out of scope
-
portal-stage.renevo.ioand any other staging or development host. They are not public; please do not test them. - Any host not listed under In scope.
- Third-party services Renevo uses: Clerk for sign-in, Stripe for payments, Resend for email, Google and Microsoft OAuth, and Cloudflare. Report those to the vendor, unless the flaw is in how Renevo integrates them.
Rules
- Use accounts you created. Test only with your own accounts. To check whether one user can reach another user’s data, create two accounts and test between them.
- Leave other people’s data alone. Never access, change or delete another user’s data. If you reach real user data, stop, do not keep or share it, and report it straight away.
- No denial of service. No denial-of-service or load testing. Keep automated
scanning gentle, at most 5 requests per second, and send the header
X-Security-Research: <your handle>so we can tell your traffic apart. - No social engineering. No social engineering, phishing or physical attacks. Do not use the product to spam other people.
- Go no further than you need. Do not use a finding to move deeper into our systems. Show the impact with the minimum needed to prove it.
- Keep it confidential until it is fixed. Keep findings confidential until we confirm the fix. We follow coordinated disclosure: 90 days from your report by default, sooner if we both agree.
Not accepted
We do not accept reports of the following.
- Scanner output without a working proof of concept
- Missing security headers or cookie flags with no demonstrated impact
- Clickjacking on pages without sensitive actions
- Self-XSS
- CSRF on logout or other actions that change no state
- Missing rate limiting on non-sensitive endpoints
- SPF, DKIM or DMARC findings without a proof of spoofing
- User or email enumeration through the sign-up flow
- Issues that only affect outdated browsers, or rooted or jailbroken devices
- Reports about software versions without a working exploit
- Vulnerabilities in third-party services (see Scope)
How to report
Email [email protected] with a subject that starts with
[Security]. Send one issue per email, and include:
- What is affected: the URL, the API endpoint or the app version
- Steps to reproduce it
- The impact: what an attacker could do with it
- Proof: requests and responses, screenshots or a video
- The email address of the test account you used
- How you would like to be credited: a handle, with an optional link, or anonymous
Never include other people’s data in a report.
What happens next
Once you have reported, this is what we commit to.
- Acknowledgement
- Within 3 business days of your email.
- First assessment
- Within 10 business days.
- Updates
- At least every 14 days until the issue is closed.
- Fix targets
- By severity: Critical 7 days, High 30 days, Medium 60 days, Low 90 days.
- When it is fixed
- We tell you.
- Credit
- A place on the leaderboard, if you want it.
Severity
We use the CVSS 3.1 base score as a guide, then adjust it for the real impact on Renevo users. Renevo makes the final call.
| Severity | CVSS 3.1 base score | Fix target | Points |
|---|---|---|---|
| Critical | 9.0 to 10.0 | 7 days | 40 |
| High | 7.0 to 8.9 | 30 days | 20 |
| Medium | 4.0 to 6.9 | 60 days | 10 |
| Low | 0.1 to 3.9 | 90 days | 5 |
| Informational | 0.0 | None | 1 |
Recognition
We do not pay cash bounties at the moment. Each valid report that we fix earns points on the public security leaderboard, by severity as in the table above. Only the first person to report an issue gets credit for it.
Safe harbour
If you research in good faith and follow this policy, we consider your research authorised. We will not take legal action against you for it, or support legal action by anyone else, and we will work with you to understand and fix the issue.
This policy does not authorise testing third-party services.
Last updated . The same contact details, in machine-readable form: security.txt.