Contact
Send vulnerability reports to security@recoverycodes.eu. Please encrypt sensitive reports with our PGP key if you have it. If PGP is unavailable, send the report as plain text and we can arrange a secure channel from there.
You can also reach this page through security.txt.
Scope
We welcome reports against the following:
- The RecoveryCodes web application at
app.recoverycodes.eu - The RecoveryCodes marketing site at
recoverycodes.eu - Infrastructure and domains under
recoverycodes.eu
Out of scope
- Social engineering or phishing
- Denial-of-service attacks
- Physical attacks against our infrastructure or offices
- Automated vulnerability scanners run without prior coordination
- Missing security headers that do not present an exploitable vulnerability
- Theoretical vulnerabilities without a working proof of concept
- Reports from automated tools that have not been verified by a human
No bug bounty
RecoveryCodes does not currently offer monetary rewards for vulnerability reports.
Safe harbor
When you research and report a vulnerability in good faith under this policy, we will not pursue legal action against you. We consider good-faith research to be testing that is limited to what is necessary to confirm a vulnerability, does not damage or exfiltrate data, and stops once the issue is confirmed.
If your testing involves third-party services (for example an OAuth provider or payment processor), you must comply with that provider's own policies.
What to include in your report
- A clear description of the vulnerability
- Steps to reproduce, including the URL and any required setup
- The impact: what an attacker could do, and under what conditions
- Any supporting material (screenshots, logs, proof-of-concept code)
What to expect from us
- We will acknowledge your report within 24 hours.
- We will keep you informed of our progress as we triage and fix the issue.
- We aim to resolve confirmed vulnerabilities within 72 hours. Critical issues are prioritized.
- Once the fix is deployed we will coordinate public disclosure with you. We ask that you do not disclose the vulnerability before we have released a fix.