# Security at Recce

## We value the contributions of security researchers in helping keep our platform safe.

## If you’ve discovered a vulnerability, please submit it using the form below. We review  every submission with care.

## Responsible Disclosure Guidelines

We ask that all researchers follow these rules to keep users safe and ensure a smooth resolution:

## Test Responsibly

### Respect privacy & availability

Avoid accessing, modifying, or deleting any user data. Do not attempt denial-of-service attacks or anything that could degrade our services.

## Scope

### Focus on our assets

Our program applies to all public services hosted under `*.reccehq.com` and our public APIs. Third-party systems and social engineering are out of scope.

## Communicate Privately

### Give us time to respond

Please report all findings privately via the embedded form below and allow us a reasonable time to investigate and remediate the issue before any public disclosure.

## Safe Harbor

### Good faith protection

We won’t pursue legal action against researchers who act in good faith, follow this policy, and avoid harming users or data.

## Submit a Report

Use the form below to securely disclose your findings to the Recce team via HackerOne.

## Program highlights

Open Scope Accepts reports for all owned assets based on impact, even if not listed in scope. [Learn more about Open Scope (opens in a new tab)](https://docs.hackerone.com/en/articles/8490833-security-page#h_46a5b35ded)

Gold Standard Safe Harbor Adheres to Gold Standard Safe Harbor. [Learn more about Gold Standard Safe Harbor (opens in a new tab)](https://docs.hackerone.com/en/articles/8494525-gold-standard-safe-harbor-statement)

Top Response Efficiency This program's response efficiency is above 90%. [Learn more about Top Response Efficiency (opens in a new tab)](https://docs.hackerone.com/en/articles/8490880-response-target-indicators)

Response targets for this program:

- Time to first response: 5 days
- Time to triage: 10 days
- Time to resolution: 30 days

1

**Weakness**

Select the type of the potential issue you have discovered.

Select Weakness Type...

2

**Severity (optional)**

Estimate the severity of this issue.

**Score**

None

0

**Attack Vector (AV)**

- **Network (N):** The vulnerable system is bound to the network stack and the set of possible attackers extends beyond the other options listed below, up to and including the entire Internet.
- **Adjacent (A):** The vulnerable system is bound to a protocol stack, but the attack is limited at the protocol level to a logically adjacent topology.
- **Local (L):** The vulnerable system is not bound to the network stack, and the attacker's path is via read/write/execute capabilities.
- **Physical (P):** The attack requires the attacker to physically touch or manipulate the vulnerable system.

**Attack Complexity (AC)**

- **Low (L):** The attacker must take no measurable action to exploit the vulnerability.
- **High (H):** The successful attack depends on the evasion or circumvention of security-enhancing techniques in place.

**Attack Requirements (AT)**

- **None (N):** The successful attack does not depend on the deployment and execution conditions of the vulnerable system.
- **Present (P):** The successful attack depends on the presence of specific deployment and execution conditions of the vulnerable system.

**Privileges Required (PR)**

- **None (N):** The attacker is unauthenticated prior to the attack.
- **Low (L):** The attacker requires privileges that provide basic capabilities typically limited to a single low-privileged user.
- **High (H):** The attacker requires privileges that provide significant (e.g., administrative) control over the vulnerable system.

**User Interaction (UI)**

- **None (N):** The vulnerable system can be exploited without interaction from any human user.
- **Passive (P):** Successful exploitation of this vulnerability requires limited interaction by the targeted user.
- **Active (A):** Successful exploitation of this vulnerability requires a targeted user to perform specific, conscious interactions with the vulnerable system.

**Vulnerable System Confidentiality Impact (VC)**

- **High (H):** There is a total loss of confidentiality.
- **Low (L):** There is some loss of confidentiality.
- **None (N):** There is no loss of confidentiality within the Vulnerable System.

**Vulnerable System Integrity Impact (VI)**

- **High (H):** There is a total loss of integrity.
- **Low (L):** Modification of data is possible, but the attacker does not have control over the consequence of a modification.
- **None (N):** There is no loss of integrity within the Vulnerable System.

**Vulnerable System Availability Impact (VA)**

- **High (H):** There is a total loss of availability.
- **Low (L):** Performance is reduced or there are interruptions in resource availability.
- **None (N):** There is no impact to availability within the Vulnerable System.

**Subsequent System Confidentiality Impact (SC)**

- **High (H):** There is a total loss of confidentiality in the Subsequent System.
- **Low (L):** There is some loss of confidentiality in the Subsequent System.
- **None (N):** There is no loss of confidentiality.

**Subsequent System Integrity Impact (SI)**

- **High (H):** There is a total loss of integrity in the Subsequent System.
- **Low (L):** Modification of data is possible, but does not have a direct, serious impact.
- **None (N):** There is no loss of integrity within the Subsequent System.

**Subsequent System Availability Impact (SA)**

- **High (H):** There is a total loss of availability in the Subsequent System.
- **Low (L):** Performance is reduced or there are interruptions in resource availability.
- **None (N):** There is no impact to availability within the Subsequent System.
