§ 1

Contact

Send vulnerability reports to security@recoverycodes.eu. Please encrypt sensitive reports with our PGP key if you have it. If PGP is unavailable, send the report as plain text and we can arrange a secure channel from there.

You can also reach this page through security.txt.

§ 2

Scope

We welcome reports against the following:

  • The RecoveryCodes web application at app.recoverycodes.eu
  • The RecoveryCodes marketing site at recoverycodes.eu
  • Infrastructure and domains under recoverycodes.eu
§ 3

Out of scope

  • Social engineering or phishing
  • Denial-of-service attacks
  • Physical attacks against our infrastructure or offices
  • Automated vulnerability scanners run without prior coordination
  • Missing security headers that do not present an exploitable vulnerability
  • Theoretical vulnerabilities without a working proof of concept
  • Reports from automated tools that have not been verified by a human
§ 4

No bug bounty

RecoveryCodes does not currently offer monetary rewards for vulnerability reports.

§ 5

Safe harbor

When you research and report a vulnerability in good faith under this policy, we will not pursue legal action against you. We consider good-faith research to be testing that is limited to what is necessary to confirm a vulnerability, does not damage or exfiltrate data, and stops once the issue is confirmed.

If your testing involves third-party services (for example an OAuth provider or payment processor), you must comply with that provider's own policies.

§ 6

What to include in your report

  • A clear description of the vulnerability
  • Steps to reproduce, including the URL and any required setup
  • The impact: what an attacker could do, and under what conditions
  • Any supporting material (screenshots, logs, proof-of-concept code)
§ 7

What to expect from us

  • We will acknowledge your report within 24 hours.
  • We will keep you informed of our progress as we triage and fix the issue.
  • We aim to resolve confirmed vulnerabilities within 72 hours. Critical issues are prioritized.
  • Once the fix is deployed we will coordinate public disclosure with you. We ask that you do not disclose the vulnerability before we have released a fix.