Skip to content

Vulnerability disclosure policy

Last updated 23 September 2026

We want to hear about security weaknesses in our own systems. This policy says what you may test, how to report what you find, and what you can expect from us.

Authorization

If you make a good-faith effort to follow this policy, we consider your research authorized. We will work with you to understand and fix the issue, and we will not recommend or pursue legal action over it. If a third party takes legal action against you over research that followed this policy, we will make it known that your research was authorized.

We can authorize testing only of systems we control. This policy cannot authorize testing of anyone else's systems.

Scope

The website at https://securityrealitycheck.com is in scope, meaning its content, headers, and configuration, which we control. Nothing else is in scope.

Our clients' systems are out of scope and are never authorized under this policy. Other hostnames that point to a provider's service, such as our mail and autodiscover records, and our providers' own platforms and infrastructure, such as Cloudflare's and Microsoft's, are also out of scope; report issues in those to the provider directly. If you are unsure whether something is in scope, ask us first.

Guidelines

  • Tell us as soon as you can after you find a real or potential issue.
  • Avoid privacy violations, degrading the service, and destroying or changing data.
  • Use an exploit only to confirm the issue. Do not access, modify, or copy data beyond the minimum needed to demonstrate it, and delete anything you did obtain once you have reported it.
  • Give us reasonable time to fix the issue before you disclose it publicly.

Not permitted

  • Denial of service, or any testing that degrades availability.
  • Social engineering, including phishing, of anyone.
  • Physical testing of any premises or equipment.

How to report

Email security@securityrealitycheck.com. Describe where the issue is, how to reproduce it, and its likely impact. You may report anonymously. Please do not include more personal or sensitive data than the report needs.

What you can expect

  • An acknowledgement within 3 business days.
  • An honest view of whether we can reproduce the issue, and updates as we fix it.
  • Credit when we disclose the issue, if you want it.

We do not run a bug bounty and do not pay for reports.

Coordinated disclosure

We aim to agree a disclosure date with you once the issue is fixed, and we will not share your identity without your permission, unless the law requires us to.

Changes

A change to this policy applies from its date forward. Every revision is dated and listed below.

  • 23 September 2026. First version.

Security Reality Check LLC is a Florida limited liability company.