Security at Recce

We value the contributions of security researchers in helping keep our platform safe.

If you’ve discovered a vulnerability, please submit it using the form below. We review every submission with care.

Responsible Disclosure Guidelines

We ask that all researchers follow these rules to keep users safe and ensure a smooth resolution:

Test Responsibly

Respect privacy & availability

Avoid accessing, modifying, or deleting any user data. Do not attempt denial-of-service attacks or anything that could degrade our services.

Scope

Focus on our assets

Our program applies to all public services hosted under *.reccehq.com and our public APIs. Third-party systems and social engineering are out of scope.

Communicate Privately

Give us time to respond

Please report all findings privately via the embedded form below and allow us a reasonable time to investigate and remediate the issue before any public disclosure.

Safe Harbor

Good faith protection

We won’t pursue legal action against researchers who act in good faith, follow this policy, and avoid harming users or data.

Submit a Report

Use the form below to securely disclose your findings to the Recce team via HackerOne.

Program highlights

Open Scope Accepts reports for all owned assets based on impact, even if not listed in scope. Learn more about Open Scope (opens in a new tab)

Gold Standard Safe Harbor Adheres to Gold Standard Safe Harbor. Learn more about Gold Standard Safe Harbor (opens in a new tab)

Top Response Efficiency This program's response efficiency is above 90%. Learn more about Top Response Efficiency (opens in a new tab)

Response targets for this program:

  • Time to first response: 5 days
  • Time to triage: 10 days
  • Time to resolution: 30 days

1

Weakness

Select the type of the potential issue you have discovered.

Select Weakness Type...

2

Severity (optional)

Estimate the severity of this issue.

Score

None

0

Attack Vector (AV)

  • Network (N): The vulnerable system is bound to the network stack and the set of possible attackers extends beyond the other options listed below, up to and including the entire Internet.
  • Adjacent (A): The vulnerable system is bound to a protocol stack, but the attack is limited at the protocol level to a logically adjacent topology.
  • Local (L): The vulnerable system is not bound to the network stack, and the attacker's path is via read/write/execute capabilities.
  • Physical (P): The attack requires the attacker to physically touch or manipulate the vulnerable system.

Attack Complexity (AC)

  • Low (L): The attacker must take no measurable action to exploit the vulnerability.
  • High (H): The successful attack depends on the evasion or circumvention of security-enhancing techniques in place.

Attack Requirements (AT)

  • None (N): The successful attack does not depend on the deployment and execution conditions of the vulnerable system.
  • Present (P): The successful attack depends on the presence of specific deployment and execution conditions of the vulnerable system.

Privileges Required (PR)

  • None (N): The attacker is unauthenticated prior to the attack.
  • Low (L): The attacker requires privileges that provide basic capabilities typically limited to a single low-privileged user.
  • High (H): The attacker requires privileges that provide significant (e.g., administrative) control over the vulnerable system.

User Interaction (UI)

  • None (N): The vulnerable system can be exploited without interaction from any human user.
  • Passive (P): Successful exploitation of this vulnerability requires limited interaction by the targeted user.
  • Active (A): Successful exploitation of this vulnerability requires a targeted user to perform specific, conscious interactions with the vulnerable system.

Vulnerable System Confidentiality Impact (VC)

  • High (H): There is a total loss of confidentiality.
  • Low (L): There is some loss of confidentiality.
  • None (N): There is no loss of confidentiality within the Vulnerable System.

Vulnerable System Integrity Impact (VI)

  • High (H): There is a total loss of integrity.
  • Low (L): Modification of data is possible, but the attacker does not have control over the consequence of a modification.
  • None (N): There is no loss of integrity within the Vulnerable System.

Vulnerable System Availability Impact (VA)

  • High (H): There is a total loss of availability.
  • Low (L): Performance is reduced or there are interruptions in resource availability.
  • None (N): There is no impact to availability within the Vulnerable System.

Subsequent System Confidentiality Impact (SC)

  • High (H): There is a total loss of confidentiality in the Subsequent System.
  • Low (L): There is some loss of confidentiality in the Subsequent System.
  • None (N): There is no loss of confidentiality.

Subsequent System Integrity Impact (SI)

  • High (H): There is a total loss of integrity in the Subsequent System.
  • Low (L): Modification of data is possible, but does not have a direct, serious impact.
  • None (N): There is no loss of integrity within the Subsequent System.

Subsequent System Availability Impact (SA)

  • High (H): There is a total loss of availability in the Subsequent System.
  • Low (L): Performance is reduced or there are interruptions in resource availability.
  • None (N): There is no impact to availability within the Subsequent System.