Report a Security Issue
Last updated: 25 July 2026
We take the security of Rekonfi and our customers' data seriously. If you believe you have found a security vulnerability, we welcome your report and will work with you to understand and resolve it quickly. This page explains how to reach us, what's in scope, and what you can expect from us.
How to report
Please email security@rekonfi.com with a description of the issue, the steps to reproduce it, and any proof-of-concept you can share. The same contact is published in our security.txt. Please do not report security issues through public channels such as social media or our general contact form.
What we'll do
- Acknowledge your report within 5 business days.
- Keep you informed of our progress as we investigate and work towards a fix.
- Credit you for the discovery, with your permission, once the issue is resolved.
We are a small team, so beyond the acknowledgement above we don't commit to a fixed resolution timeline. We do not operate a paid bug-bounty programme, but genuine reports are genuinely appreciated and taken seriously.
Scope
In scope: the Rekonfi web application and the rekonfi.com domain and its subdomains.
The following are out of scope:
- Third-party services we integrate with (for example Finexer, QuickBooks Online, Xero, Sage, and our analytics and email providers) — please report issues in those products to their respective vendors.
- Denial-of-service, volumetric, or other availability-degrading attacks, and any automated scanning that generates significant load.
- Social engineering of our staff or customers, and physical attacks.
- Reports from automated tools without a demonstrable, exploitable proof-of-concept.
Safe harbour
We will not pursue or support legal action against anyone who reports a vulnerability in good faith and in accordance with this policy. To stay within it, please act in good faith to avoid privacy violations and disruption to our services: only interact with accounts you own or have explicit permission to test, do not access, modify, or destroy other people's data, and give us a reasonable opportunity to resolve the issue before disclosing it publicly.