Legal & Governance
Responsible Disclosure
Last updated: 9 October 2026
Responsible Disclosure
Last updated: 9 October 2026
We take the security of our systems seriously, and we welcome reports from security researchers who find vulnerabilities in them.
How to report
Email security@redblacktree.com with:
- a description of the vulnerability and where it is (URL or system);
- the steps to reproduce it, and a proof of concept if you have one;
- the potential impact, as you understand it; and
- how you’d like to be credited, if at all.
Please don’t include more personal data than you need to demonstrate the issue.
What we ask of you
- Give us reasonable time to fix the issue before telling anyone else.
- Don’t access, change or delete data that isn’t yours, and stop as soon as you’ve confirmed a vulnerability.
- Don’t degrade our services: no denial-of-service testing, spam, or automated scanning that generates heavy traffic.
- Don’t use social engineering, phishing or physical attacks against our people or offices.
- Don’t test systems that belong to our clients. Their software isn’t covered by this policy, even if we built it.
What we commit to
- We’ll acknowledge your report within five working days.
- We’ll keep you informed as we investigate and fix it.
- If you’ve acted in good faith and within this policy, we won’t pursue or support legal action against you for your research.
- With your permission, we’ll credit you once the issue is fixed.
We don’t currently offer a paid bug bounty.
In scope
www.redblacktree.com and its subdomains operated by RedBlackTree.