← All policies

Vulnerability Disclosure Policy

Last updated: 2026-07-25


0. About this Policy

Recovea, Inc., a Delaware corporation ("Recovea," "we," "us," or "our"), with its notice address at 2810 N Church St STE 89986, Wilmington, DE 19802, depends on the security and integrity of the infrastructure we operate. We value the work of independent security researchers and the broader security community, and we want to make it safe, predictable, and lawful for you to find and report security vulnerabilities to us.

This Vulnerability Disclosure Policy (this "Policy") explains:

  • what systems are in scope (and, importantly, what is out of scope);
  • how to report a vulnerability to us;
  • what you can expect from us in return; and
  • the legal safe harbor we extend to good-faith security research conducted in accordance with this Policy.

This Policy is a vulnerability disclosure program (VDP), not a paid bug-bounty program. As described in Section 8, we do not offer monetary rewards or any bounty at this time, and participation does not create any obligation by Recovea to pay you.

Acceptance. By submitting a Report or conducting security research under this Policy, you accept and agree to these terms, including the eligibility requirements (Section 1A), rules of engagement (Section 5), license grant (Section 9), disclaimers (Section 11), limitation of liability (Section 12), and governing-law and forum terms (Section 13). If you do not agree, do not submit a Report and do not conduct research under this Policy.

Consideration. The authorization and legal safe harbor extended under this Policy (Section 6) are the consideration for the license, waivers, releases, representations, and other commitments you make by submitting a Report or conducting research under this Policy. You and Recovea each acknowledge this exchange of value as sufficient consideration to make the terms of this Policy binding and enforceable.

Recovea is a bootstrap-funded US company; nothing in this Policy concerns investment or securities.

We have designed and operate this Policy to be aligned with the principles of ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling processes). We are not certified to, audited against, or formally compliant with those standards, and reference to them is descriptive only.


1. Definitions

For purposes of this Policy:

  • "In-Scope Systems" means the Recovea-owned and Recovea-operated assets expressly listed in Section 3.1, and only those assets.
  • "Out-of-Scope Systems" means everything described in Section 3.2, including all third-party systems and services.
  • "Vulnerability" (also a "Recovea Vulnerability") means a weakness in an In-Scope System that could be exploited to compromise the confidentiality, integrity, or availability of that system or the data it processes. For clarity, the behavior of underlying third-party Provider models is not a Recovea Vulnerability (Section 3.2).
  • "Report" means a vulnerability submission made to us through the channel in Section 4.
  • "Reporter" (or "you") means the individual or entity that submits a Report or conducts research under this Policy.
  • "Good-Faith Security Research" means accessing or interacting with an In-Scope System solely to identify, test, and report a Vulnerability, in accordance with this Policy, carried out in a manner designed to avoid harm to Recovea, our customers, our users, or any third party, and without intent to defraud, extort, harm, or misappropriate data.
  • "Services" means the suite of products, applications, APIs, gateways, dashboards, tooling, and related offerings that Recovea makes available, as defined in our Terms of Service and Master Services Agreement. The Services may include optimization, additional features and capabilities Recovea may offer; any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this Policy unless Recovea expressly states otherwise.
  • "Provider", "Provider Keys", "Inference Content", "Usage Data", "the Ledger", "Customer Personal Data", "Customer", and "Authorized User" have the meanings given to them in our Terms of Service, Master Services Agreement, Data Processing Addendum, and related agreements (collectively, the "Agreements").

Capitalized terms not defined here have the meanings given in the Agreements.


1A. Eligibility

To participate in this Policy and to be eligible for its authorization, safe harbor, and any recognition, you must satisfy all of the following at the time of your research and your Report:

  • Age of majority. You must be at least the age of majority in your jurisdiction of residence (and at least 18 years old). This Policy is not available to minors.
  • No sanctioned or embargoed persons or locations. You must not be (a) located in, ordinarily resident in, or organized under the laws of any Embargoed Jurisdiction — any country or region subject to comprehensive US economic sanctions or embargo, as illustratively enumerated in Recovea's Export Control & Sanctions Policy §3.2, which is the single source of that list and controls it (this Policy deliberately does not restate the enumeration, so the two can never drift); or (b) a person or entity identified on any US government restricted-, denied-, or sanctioned-party list, including the US Treasury Department's Office of Foreign Assets Control (OFAC) Specially Designated Nationals and Blocked Persons List, the US Commerce Department's Denied Persons or Entity List, or any equivalent list, or owned or controlled by any such person.
  • Export and sanctions compliance. Your research and Report must comply with all applicable US export-control and economic-sanctions laws and regulations.
  • Not Recovea personnel or insiders. You must not be a current Recovea employee, officer, director, contractor, or temporary worker, or an immediate family member or member of the household of any of the foregoing. Current Recovea personnel must use Recovea's internal security-reporting processes, not this Policy.

If you do not meet these eligibility requirements, you are not authorized to conduct research under this Policy, the safe harbor does not extend to you, and you are not eligible for recognition. Recovea may withhold authorization, safe harbor, or recognition where extending it would violate applicable law.


2. Our Commitments to You

If you make a Good-Faith Security Research effort and comply with this Policy, we commit to:

  1. Respond. Acknowledge receipt of your Report, generally within five (5) business days.
  2. Investigate. Triage and validate the reported Vulnerability and keep you reasonably informed of our progress.
  3. Remediate. Work in good faith to remediate validated Vulnerabilities on a risk-prioritized basis.
  4. Coordinate. Work with you on coordinated disclosure timing as described in Section 7.
  5. Safe harbor. Treat your Good-Faith Security Research as authorized and not pursue or support legal action against you for it, as described in Section 6.
  6. Recognize. Where you wish, and at our discretion, acknowledge your contribution as described in Section 8.

These are operational commitments, not contractual warranties, and are subject to the disclaimers in Section 11.


3. Scope

3.1 In-Scope Systems (Recovea-owned assets only)

This Policy covers only assets that Recovea owns and operates. The authoritative, machine-readable list of in-scope hostnames and our security contact is published at https://recovea.ai/.well-known/security.txt (the "security.txt" file). The assets below are intended to match that security.txt file; if the two ever conflict, the security.txt file controls.

In-Scope Systems include:

  • recovea.ai and the marketing/web properties we control;
  • platform.recovea.ai — the Recovea customer dashboard and control plane;
  • console.recovea.ai — the internal operator console;
  • api.recovea.ai — the Recovea in-path API gateway (OpenAI-compatible /v1, Anthropic /anthropic, and OpenRouter-compatible long-tail endpoints);
  • Recovea control-plane endpoints that Recovea exposes under a recovea.ai hostname; and
  • Recovea-published client tooling that Recovea authors and distributes, to the extent published and distributed by Recovea and to the extent a Vulnerability resides in code that Recovea authors and distributes. The current, authoritative inventory of in-scope client tooling is the security.txt file; tooling is in scope only if and to the extent it is listed there.

Only Vulnerabilities affecting these Recovea-owned and Recovea-operated assets are in scope. If you are unsure whether a target is in scope, ask us first at the address in Section 4 before testing.

Recovea-specific areas of interest. Because Recovea operates an in-path API gateway, we particularly welcome Good-Faith Security Research on the integrity of our gateway controls, including:

  • bypass or defeat of spend caps, budget limits, rate limits, or kill-switch / circuit-breaker controls;
  • metering, billing, or usage-attribution manipulation (for example, causing usage to be misattributed, undercounted, or attributed to another tenant);
  • tenant-attribution or tenant-isolation weaknesses that could cause one Customer's activity, data, or controls to affect another (using only your own test accounts — see Section 5); and
  • integrity of the Ledger, including any hash-chain, tamper-evidence, or record-integrity weakness that would allow Ledger records to be altered, forged, reordered, or deleted without detection.

These examples are illustrative, not exhaustive, and remain subject to the scope boundaries and rules of engagement below.

3.2 Out-of-Scope Systems and Findings

The following are expressly out of scope. Do not test, probe, scan, or attack them under this Policy, and this Policy's authorization and safe harbor do not extend to them:

  • Third-party model Providers and their accounts, APIs, models, infrastructure, and credentials — including, without limitation, OpenAI, Anthropic, and OpenRouter. Recovea operates a bring-your-own-key (BYO-Key), in-path conduit model: the Customer brings and owns its own Provider accounts, relationships, and API keys, and pays the Providers directly. Recovea does not resell, mark up, sponsor, or take custody of Provider tokens or Provider spend, and is not a party to the Customer's agreements with its Providers. Provider systems are not Recovea assets and are out of scope.
  • Behavior of underlying third-party Provider models. Model outputs, hallucinations, accuracy, content- and safety-moderation behavior, refusals, bias, and the prompt-injection or jailbreak susceptibility of any underlying third-party Provider model are not Recovea Vulnerabilities. Recovea is a conduit and does not control, warrant, or guarantee the content, quality, or safety behavior of Provider models. Report such matters to the relevant Provider, not to us. (A flaw in how the Recovea gateway itself enforces its own controls — for example, defeating a Recovea cap, kill-switch, metering, or tenant-attribution control — is in scope under Section 3.1, even if a prompt is involved.)
  • Cloud and platform infrastructure operated by our vendors, including our cloud infrastructure provider, our payments processor (Stripe), and our email/identity infrastructure. Vulnerabilities in these underlying platforms must be reported to the respective vendor under that vendor's own disclosure program, not to us. (A vulnerability in how Recovea configures or uses an In-Scope System is, however, in scope.)
  • Any other third-party service, website, integration, library, or open-source dependency not authored and distributed by Recovea, even if it is reachable from or linked to a Recovea property.
  • Customer-owned systems, Customer Personal Data, other Customer data, Provider Keys, and Inference Content. Do not attempt to access, intercept, exfiltrate, or interact with any Customer's traffic, account, keys, or content, and do not target other tenants.
  • Physical security of Recovea or vendor facilities; social engineering of Recovea personnel, customers, or vendors; and any attack on personal accounts or devices of Recovea staff.

Non-qualifying findings. The following are generally not treated as qualifying Vulnerabilities and, on their own, will usually be closed as informational. We still welcome a Report where you can demonstrate a concrete, exploitable security impact on an In-Scope System:

  • missing or misconfigured security headers (for example, CSP, HSTS, X-Frame-Options) without a demonstrated exploit;
  • absence of rate-limiting, or rate-limiting concerns, without a demonstrated impact;
  • self-XSS, or issues requiring the victim to paste attacker-supplied content into their own session;
  • raw output of automated scanners or vulnerability tools without validation or a working proof-of-concept;
  • SPF, DKIM, or DMARC configuration notes and other email best-practice recommendations;
  • software version-banner or fingerprint disclosure without an associated, exploitable weakness;
  • clickjacking on pages with no sensitive state-changing action;
  • theoretical issues without a realistic, demonstrated attack scenario.

If your research necessarily touches an Out-of-Scope System, stop and contact us before proceeding.


4. How to Report

Send Reports to security@recovea.ai. This is the security reporting channel published in our security.txt file.

To help us triage quickly, please include, where you can:

  • a clear description of the Vulnerability and the In-Scope System affected (with the exact hostname or asset);
  • the steps required to reproduce it (a minimal proof-of-concept is ideal);
  • the type and potential impact of the Vulnerability;
  • any tools, payloads, accounts, or IP addresses you used;
  • your assessment of severity; and
  • how you would like to be credited (or that you prefer to remain anonymous).

Please report in English, and please submit one Vulnerability per Report where practicable.

Encryption. Recovea publishes no PGP key today, and our security.txt deliberately carries no Encryption field rather than advertise a key we do not operate. If you wish to encrypt sensitive details, ask us at security@recovea.ai and we will exchange keys before you transmit them. Do not run live exploit payloads against production beyond what is minimally necessary to demonstrate the issue.

Do not report security Vulnerabilities through public channels, social media, support tickets, sales channels, or by filing public issues. Public disclosure before coordinated remediation is outside this Policy (see Section 7).


5. Rules of Engagement

To stay within this Policy and its safe harbor, you must:

  • Only test In-Scope Systems (Section 3.1), and only to the minimum extent necessary to identify and demonstrate a Vulnerability.
  • Avoid harm. Do not perform actions that could degrade, disrupt, or deny service to Recovea, our customers, or our users — including no denial-of-service (DoS/DDoS), no resource-exhaustion or volumetric testing, no automated high-rate scanning that impairs availability, no spam, and no destructive testing.
  • Respect data. Do not access, modify, delete, store, retain, or exfiltrate any data that is not your own. If you encounter any Customer Personal Data, other Customer data, Provider Keys, Inference Content, Usage Data, personal data, credentials, or other sensitive information, stop immediately, do not view or copy more than the minimum needed to confirm the issue, document only what is necessary, notify us promptly, and securely delete any such data in your possession at our request.
  • Use only your own test accounts. Do not pivot to other tenants, accounts, or users. Do not attempt to break tenant isolation in a way that exposes another party's data.
  • No persistence, no backdoors. Do not install malware, create persistent accounts, or maintain access after you have demonstrated the Vulnerability.
  • No extortion. Do not condition disclosure on payment, and do not threaten to release, sell, or exploit a Vulnerability. Extortion is not Good-Faith Security Research and voids the safe harbor.
  • Comply with applicable law and your Agreement. Conduct your research lawfully and consistent with this Policy. If you are a Customer or Authorized User, also comply with your Agreement (including its Acceptable Use Policy). Nothing in this Policy authorizes you to violate any law.
  • Keep it confidential. Give us a reasonable opportunity to remediate before any disclosure (Section 7), and do not publicly disclose Vulnerability details without coordinating with us.

Activities that fall outside these rules are not authorized and are not covered by the safe harbor.


6. Legal Safe Harbor

We want to make it safe for you to do the right thing. Subject to your good-faith compliance with this Policy and your eligibility under Section 1A:

  1. Authorization. We consider Good-Faith Security Research conducted in accordance with this Policy to be authorized access to our In-Scope Systems. We will not treat it as a violation of, and we authorize it under, the U.S. Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030. Consistent with Van Buren v. United States, 593 U.S. 374 (2021), accessing an In-Scope System for purposes authorized by this Policy is not access that "exceeds authorized access."
  1. DOJ good-faith framework. We intend this Policy to be consistent with the U.S. Department of Justice's policy of declining to charge good-faith security research under the CFAA (DOJ, Charging Policy for Computer Fraud and Abuse Act Cases, May 2022). Research conducted to promote the security or safety of the systems tested — and not to cause harm or for extortion or other illegitimate purpose — is "good-faith security research" for which we extend authorization.
  1. DMCA § 1201. To the extent your Good-Faith Security Research involves circumventing a technological protection measure on an In-Scope System, we authorize that circumvention solely for the purpose of Good-Faith Security Research under this Policy, consistent with the security-research provisions of the Digital Millennium Copyright Act, 17 U.S.C. § 1201(j) and the Librarian of Congress's security-research exemptions. We will not bring a DMCA § 1201 claim against you for such authorized, good-faith activity.
  1. No anti-circumvention or contract claims for in-scope, good-faith work. We waive any claim under our Agreements' restrictions (including any anti-circumvention, no-reverse-engineering, or access-restriction terms) only to the extent, and only for activity, that is (a) Good-Faith Security Research, (b) on In-Scope Systems, and (c) in compliance with this Policy. Other terms of the Agreements remain in effect.
  1. We will not sue or support prosecution. If you make a good-faith effort to comply with this Policy, we will not initiate, pursue, recommend, or support any civil action or criminal complaint against you arising from your security research, and, if a third party brings an action against you for activity that was authorized under this Policy, we will take reasonable steps to make known that the activity was authorized. For the avoidance of doubt, nothing in this Policy obligates Recovea to defend, indemnify, advance fees to, hold harmless, or appear as a party on behalf of any Reporter; "reasonable steps" means, at most, a written confirmation that the activity was authorized under this Policy.

Limits of the safe harbor. This safe harbor:

  • applies only to claims that Recovea is legally entitled to waive or to decline to pursue;
  • does not bind any third party, including any Provider, our cloud infrastructure provider, our payments processor, any other vendor, any Customer, or any government authority. We cannot and do not authorize you to test, or waive any rights of, any Out-of-Scope System or third party;
  • does not apply to activity outside scope, in violation of the rules in Section 5, by a person who is not eligible under Section 1A, or otherwise not in good faith; and
  • does not authorize any violation of law.

If you are uncertain whether specific conduct is consistent with this Policy, ask us first at security@recovea.ai, and we will work with you in good faith to clarify. If you act in good faith and inadvertently or in good-faith uncertainty step outside these guidelines, we will consider that good faith when deciding how to respond, consistent with the spirit of Van Buren and the DOJ good-faith framework.


7. Coordinated Disclosure

We follow a coordinated disclosure model and ask the same of you.

  • Embargo. Please keep the details of any Vulnerability confidential until we have had a reasonable opportunity to investigate and remediate, and until we mutually agree on disclosure.
  • Default window. Our default coordinated-disclosure window is approximately ninety (90) days from the date we acknowledge your Report. We will make reasonable efforts to remediate within that window and to coordinate public disclosure timing with you.
  • Extensions. Some issues are complex or depend on third parties. Where remediation reasonably requires more time, we may ask you to extend the window; we will keep you informed and explain why.
  • Active exploitation. If a Vulnerability is being actively exploited, or poses imminent risk, we may accelerate remediation and disclosure, and we ask that you coordinate closely with us.
  • No unilateral public disclosure. Please do not publicly disclose, demonstrate, or share Vulnerability details (including to third parties or in talks, blogs, or social media) before the coordinated date without our written agreement. Coordinated public disclosure that follows this Policy is within its safe harbor; unilateral early disclosure is not.

We will credit and coordinate with you on any public advisory, where you wish to be named.

This Policy aligns with the coordinated-disclosure and vulnerability-handling principles of ISO/IEC 29147 and ISO/IEC 30111; Recovea is not certified to those standards.


8. No Bounty; Recognition Only

This is a vulnerability disclosure program, not a bug-bounty program.

  • We do not currently offer, and are under no obligation to provide, any monetary reward, bounty, payment, gift, swag, or other compensation for any Report.
  • Submitting a Report does not create any contract for compensation, expectation of payment, or entitlement of any kind, and you waive any claim to compensation for a Report.
  • At our sole discretion, and only where you wish to be identified, we may offer recognition — such as a thank-you or acknowledgment in a security advisory or "hall of fame." Recognition is discretionary, not guaranteed, and may be withheld (for example, for low-impact, duplicate, non-qualifying, or out-of-scope Reports, or where recognition would be unlawful, including under Section 1A).
  • We may, in the future and at our sole discretion, introduce a rewards or bounty program with its own separate terms. This Policy does not promise that we will do so.

9. Ownership of Reports; License

By submitting a Report or conducting research under this Policy, you accept and agree to these terms; if you do not agree, do not submit. You further agree that:

  • you grant Recovea a perpetual, irrevocable, worldwide, royalty-free, non-exclusive, sublicensable, and transferable license to use, reproduce, modify, distribute, and act upon the Report and its contents for any lawful purpose, including investigating and remediating the Vulnerability and improving our security and Services;
  • you will not be entitled to any compensation for the Report (Section 8);
  • to the extent you include any feedback, suggestions, or ideas, you assign them to us or grant us an unrestricted license to use them without obligation or attribution; and
  • you represent and warrant that you are eligible under Section 1A, that your Report does not contain any third party's confidential information or any data you were not authorized to access, and that your submission does not violate any third party's rights or any applicable law.

We will treat your Report and your identifying information as confidential and handle any personal data you provide in accordance with our Privacy Policy.


10. Relationship to Our Agreements and Privacy/Security Practices

  • Cross-references. This Policy is a standalone security document. It does not modify the Agreements (Terms of Service, Master Services Agreement, Data Processing Addendum, BYO-Key Addendum, Acceptable Use Policy, Security Statement, or Privacy Policy). In the event of a conflict between this Policy and an Agreement on a matter the Agreement governs, the Agreement controls — except that the safe-harbor authorizations in Section 6 govern the scope of authorized security research as against access-restriction terms.
  • Customer use. If you are a Recovea Customer or Authorized User, your testing of the Services is also governed by your Agreement (including its Acceptable Use Policy). This Policy authorizes Good-Faith Security Research on In-Scope Systems notwithstanding general no-probing/no-circumvention terms, but does not otherwise relax your Agreement.
  • Security practices. Recovea's security posture is described in our Security Statement, which is the conservative, authoritative description of what is and is not live. Nothing in this Policy is a representation about the security or invulnerability of any system. Where the Security Statement marks a control as planned rather than live, no statement here implies otherwise.
  • Data handling. Our handling of any personal data in Reports, and the immutable-Ledger integrity carve-out and erasure mechanics described in our Privacy Policy and DPA, apply to data we hold; they are not altered by this Policy.

11. No Warranty; Disclaimers

THE IN-SCOPE SYSTEMS AND THIS POLICY ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND. TO THE FULLEST EXTENT PERMITTED BY LAW, RECOVEA DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, AND STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. NOTHING IN THIS POLICY IS A REPRESENTATION OR WARRANTY THAT ANY SYSTEM IS SECURE, FREE OF VULNERABILITIES, OR ERROR-FREE, OR THAT ANY OUTPUT OF AN UNDERLYING THIRD-PARTY PROVIDER MODEL IS ACCURATE, SAFE, OR FIT FOR ANY PURPOSE.

Participation in this Policy is voluntary and at your own risk. You are responsible for complying with all applicable laws in conducting your research, and you alone bear the legal consequences of any activity that falls outside the scope and rules of this Policy.


12. Limitation of Liability

TO THE FULLEST EXTENT PERMITTED BY LAW, RECOVEA, ITS OFFICERS, DIRECTORS, EMPLOYEES, AND AGENTS WILL NOT BE LIABLE TO ANY REPORTER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR ANTICIPATED COMPENSATION, ARISING OUT OF OR RELATING TO THIS POLICY OR YOUR PARTICIPATION IN IT, REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. THIS POLICY IS NOT A PAID ENGAGEMENT AND CREATES NO PAYMENT OBLIGATION; ACCORDINGLY, RECOVEA'S AGGREGATE LIABILITY TO ANY REPORTER ARISING FROM OR RELATING TO THIS POLICY IS LIMITED TO ONE HUNDRED U.S. DOLLARS (US $100) OR THE MINIMUM AMOUNT PERMITTED BY APPLICABLE LAW, WHICHEVER IS GREATER. SOME JURISDICTIONS DO NOT ALLOW CERTAIN OF THESE LIMITATIONS; IN SUCH JURISDICTIONS LIABILITY IS LIMITED TO THE GREATEST EXTENT PERMITTED BY LAW. THE FOREGOING LIMITATIONS ARE A FUNDAMENTAL BASIS OF THE BARGAIN BETWEEN YOU AND RECOVEA AND APPLY NOTWITHSTANDING ANY FAILURE OF ESSENTIAL PURPOSE OF ANY LIMITED REMEDY.


13. Governing Law and Forum (Non-Party Statement)

This Policy, and any dispute arising out of or relating to it or to security research conducted under it, is governed by the laws of the State of Delaware, USA, excluding its conflict-of-laws rules.

Reporters are not parties to Recovea's customer Agreements. Because a Reporter acting under this Policy is not a contracting Customer, any arbitration clause, class-action waiver, or other dispute-resolution term in Recovea's Agreements does NOT apply to a Reporter or to disputes arising from security research under this Policy. Instead, any such dispute that cannot be resolved informally will be brought exclusively in the state or federal courts located in Wilmington, Delaware, and the Reporter and Recovea irrevocably consent to the personal jurisdiction and venue of those courts and waive any objection based on inconvenient forum. Each party will bear its own costs and fees except as a court may otherwise award.

This non-party forum carve-out is intended to read consistently with the non-contracting-party forum provisions used elsewhere in our security and IP-complaint policies (for example, our DMCA notice procedure).


14. General

  • Modification. We may modify this Policy at any time by posting an updated version with a new "Last updated" date. The version in effect when you conduct your research governs that research. Material changes take effect on posting.
  • No waiver. Our failure to enforce any provision is not a waiver of our right to do so later.
  • Severability. If any provision of this Policy is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable while preserving its intent.
  • No third-party beneficiaries. This Policy does not create rights in any third party, including any Provider, vendor, or Customer.
  • Assignment. We may assign this Policy in connection with a merger, acquisition, or sale of assets, or otherwise. You may not assign your rights or obligations under it.
  • Survival. Sections 1, 1A, 6 (as to authorizations already extended for completed research), 8, 9, 11, 12, 13, and 14, and any other provision that by its nature should survive, survive the conclusion of your research, withdrawal of authorization, or modification or termination of this Policy.
  • Entire understanding. This Policy is the entire understanding between you and Recovea regarding Good-Faith Security Research on In-Scope Systems and supersedes any prior or contemporaneous understanding on that subject, except as expressly cross-referenced.
  • Electronic communications. You consent to receive communications from us electronically, and you agree that electronic communications satisfy any legal requirement that such communications be in writing.
  • Notices. Notices to Recovea under this Policy must be sent to security@recovea.ai and, for legal notices, to legal@recovea.ai (or to our notice address: 2810 N Church St STE 89986, Wilmington, DE 19802). Notices to you will be sent to the contact details in your Report.

15. Contact

  • Security reports: security@recovea.ai
  • security.txt: https://recovea.ai/.well-known/security.txt
  • Legal: legal@recovea.ai
  • Privacy: privacy@recovea.ai

Thank you for helping keep Recovea and our customers secure.


This Policy is aligned with the principles of ISO/IEC 29147 and ISO/IEC 30111 and reflects the U.S. CFAA / Van Buren, DOJ good-faith security-research, and DMCA § 1201(j) frameworks. Recovea is not certified to any standard referenced here.