Security Policy & Responsible Disclosure

Effective: 2026-05-20 · Version 1.0.

Report a vulnerability

Email security@reservory.com or submit through our private HackerOne program (invite available on request). Encrypt sensitive findings with our PGP key at /.well-known/pgp-key.txt.

Acknowledgement within 2 business days. Triage outcome within 5 business days.

1. In scope

2. Out of scope

3. What we're looking for

High-impact findings that align with our threat model:

4. Reward tiers

Bounties are paid in USD via HackerOne after a fix is shipped. Severity is decided by Reservory using CVSS 3.1 as a guide, weighted toward real-world impact in our environment.

$5,000 minimum payout for any confirmed cross-tenant data exposure. Duplicates are not paid.

5. Disclosure timeline

We follow a coordinated 90-day disclosure window from the date of triage confirmation. We may request an extension with mutual agreement if the fix has cross-system implications (e.g. a database migration affecting all tenants). We will not seek indefinite embargoes.

Researchers may publish their findings after the 90-day window or after we've confirmed the fix is live, whichever comes first. We'll credit you on our acknowledgments page unless you prefer to stay anonymous.

6. Safe harbor

We will not pursue legal action against researchers who, in good faith:

We consider activity under this policy to be authorized, and we will work with you to quickly resolve any unintentional violations. If a third party initiates legal action against you for activity that complied with this policy, we will make it known that your actions were authorized.

7. Out-of-program rules

8. Contact

security@reservory.com · PGP at /.well-known/pgp-key.txt · machine-readable policy at /.well-known/security.txt.