Responsible Disclosure
Report security issues safely.
We welcome good-faith reports that help protect REVORY customers.
- Version
- 2026.07.22
- Effective
- July 22, 2026
- Provider
- Ametrine Labs
How to report
Email security@revory.app with a concise description, affected URL or component, reproduction steps and impact. Use test data and remove secrets. We will acknowledge and triage in a commercially reasonable manner but do not promise a fixed response or bounty.
In scope
REVORY-owned application and API authorization, workspace isolation, authentication, import handling, exports, billing-event handling and accidental disclosure of REVORY-managed data.
Out of scope
Social engineering, phishing, denial of service, credential stuffing, spam, physical attacks, testing third-party infrastructure outside REVORY’s control, automated high-volume scanning, and issues requiring access to another person’s data.
Safe harbor
If you act in good faith, avoid privacy harm and disruption, test only accounts/data you control, stop when sensitive data appears, do not extort or publicly disclose before remediation, and follow this policy, we will not pursue action merely for that compliant research. This does not authorize violation of law or third-party rights.