Coordinated vulnerability disclosure

Report safely. Preserve users. Fix the root cause.

Effective July 11, 2026. This policy authorizes good-faith research within the scope and rules below.

Reporting route

Send enough detail to reproduce the issue safely.

Email security@reaperci.dev

Include the affected component and version, impact, prerequisites, minimal reproduction, and a safe contact method. Use an encrypted attachment only after coordinating a key.

Never send production credentials, private keys, customer content, or exploit data unrelated to the finding.

Start a security report

Research scope

Prove impact without widening it.

In scope

  • Released ReaperCI core, CLI, connector, installer, images, and release pipeline
  • ReaperCI-managed domains and services explicitly owned by the operator
  • Authentication, authorization, tenant isolation, secrets, approvals, audit integrity, connector boundaries, and supply-chain verification
  • Material data exposure, deployment-safety bypass, remote execution, or cross-tenant impact

Not authorized

  • Customer-tenant or third-party provider testing
  • Social engineering or physical attacks
  • Denial of service or high-volume automated scanning
  • Persistence, destructive actions, or access beyond the minimum proof

Rules of engagement

Use infrastructure you control.

Use only accounts and systems you own or have explicit permission to test. Minimize access, stop after proving impact, avoid persistence, do not alter or delete data, do not degrade availability, and allow a reasonable remediation period before disclosure.

Safe harbor

Good-faith research is welcome.

When research follows this policy, is intended to improve security, and complies with applicable law, ReaperCI will treat it as authorized, will not initiate legal action for the research, and will work to clarify ambiguity. This safe harbor cannot bind third parties or excuse unrelated unlawful conduct.

Response targets

Clear checkpoints while remediation is open.

These targets are not a bug-bounty promise or production SLA. ReaperCI does not currently offer monetary rewards.

  1. 01
    Within three business days

    Acknowledge a complete report.

  2. 02
    Within seven business days

    Provide an initial severity and scope assessment.

  3. 03
    At least every fourteen days

    Send a status update while remediation remains open.

  4. 04
    Critical findings

    Prioritize immediate containment and a coordinated release.

Disclosure

Coordinate publication so users can update safely.

ReaperCI will publish advisories for material released-product issues, including affected versions, impact, mitigations, fixed versions, and reporter credit when requested and legally permissible. If communication stops or users face imminent harm, contact us again before disclosing.

Return to security and trust