RedEye Security designs and operates security software. We hold our own products to the standard we ask of others: report a vulnerability and we will investigate it in good faith and coordinate disclosure with you.
Last updated: 23 June 2026
This policy explains what we accept reports on, how to send one, and what you can expect in return.
We accept vulnerability reports for products and services that RedEye Security builds and operates:
feeds.redeyesecurity.com.redeyesecurity.com and its subdomains, where a finding represents a genuine security risk to RedEye or its users.If you are unsure whether something is in scope, send the report anyway. We would rather receive a borderline report than miss a real issue.
RedEye Security is establishing a CVE Numbering Authority (CNA) program. Our intended CNA scope will be limited to vulnerabilities in RedEye Security's own products — the products listed above. We assign CVE IDs only for issues in our own products. Reports about our web properties or feed data are accepted and fixed, but are not CVE-eligible. For a vulnerability outside our scope, we will refer you to the appropriate CNA or to the CVE Program, and we will not assign a CVE ID ourselves.
Email [email protected] with as much of the following as you can provide:
If your report contains sensitive details and you require an encrypted channel, say so in a first email to [email protected] and we will arrange one. Please send one report per vulnerability, and please report the issue to us before disclosing it anywhere else.
RedEye Security supports security research conducted in good faith. If you make a sincere effort to comply with this policy during your research, we will consider that research authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you.
To stay within good faith, you must:
This safe harbor applies only to RedEye Security's own conduct. It cannot waive the rights of third parties, and it does not authorize activity against systems we do not own or operate. If a third party brings legal action against you for activity that complied with this policy, we will make our authorization of that research known.
We practice coordinated disclosure. We ask that you keep findings confidential until we have published a fix or advisory, and we commit in return to clear, predictable handling. Our target timelines from receipt of a valid report:
| Stage | Target |
|---|---|
| Acknowledgement | Within 3 business days |
| Triage and initial assessment | Within 10 business days |
| Status updates | At least every 14 days while the issue is open |
| Fix and advisory | Within 90 days, depending on severity and complexity |
| CVE assignment | At validation, with the CVE ID published in the advisory at disclosure |
For most issues we aim to coordinate a public disclosure date with you once a fix is available. If we cannot meet the 90-day target — for example, a deep architectural fix — we will explain why and agree on a revised timeline with you.
If a vulnerability is being actively exploited, we may disclose sooner to protect users. And if a vulnerability for which we have reserved a CVE ID is publicly disclosed by another party before our coordinated date, we will publish the corresponding CVE record within 72 hours, as required by the CVE Program. We will tell you if either happens.
We publish our security advisories openly, with no login or registration required, at https://redeyesecurity.com/security/advisories.
RedEye Security does not currently operate a paid bug-bounty program. We recognize researchers through public credit in our advisories.
The following are generally not eligible under this policy. Reports limited to these will usually be closed without action:
Activity that falls outside good-faith research — destroying data, degrading service, accessing more data than needed to prove an issue, or extorting RedEye Security — is not authorized and is not protected by the safe harbor above.
We may update this policy as our products and the disclosure landscape evolve. The current version always lives at https://redeyesecurity.com/security. Material changes apply only to reports received after the change is published.
RedEye Security · [email protected] · security.txt · CVE Numbering Authority (CNA) — application in progress