Report a security vulnerability (responsible disclosure)

How to report a security issue to Reality Twin, our response timelines, and how researchers get credit.

Updated June 2, 2026 5 min read

We take security seriously and welcome responsible disclosure from independent researchers. This article covers scope, how to report, what to expect, and public credit.

How to report

  1. Email hello@realitytwin.io with a clear description, reproduction steps and expected impact.
  2. For sensitive reports, encrypt with our PGP key (available on request).
  3. Do not test on other customers' workspaces.
  4. Do not exfiltrate real data — a proof-of-concept in your own workspace is fine.

What to expect

  • Acknowledgement within one business day.
  • Triage and severity assessment within 3 business days.
  • Remediation timeline shared within 5 business days.
  • A follow-up when the fix is deployed.
  • Public credit on /security with your consent.

In scope

  • realitytwin.io and all *.realitytwin.io subdomains.
  • The chat widget served from api/public/embed.
  • The public REST API.
  • The Reality Twin marketplace and profile pages.

Out of scope

  • Social engineering of employees or customers.
  • Physical attacks against our offices or cloud providers.
  • Denial-of-service attacks against production.
  • Findings that require a stolen device or a rooted phone.
  • Reports from automated scanners without proof of exploitability.

Rewards

We don't run a public bounty programme yet. For severe issues we offer swag, credits, and — with permission — a public thank-you on /security.

Frequently asked questions

Do you have a security.txt?

Yes — at /.well-known/security.txt.

Can I disclose publicly after remediation?

Yes, and we encourage it. Coordinate the date with us so we can prepare a joint communication.

Did this article solve your problem?

If not, email us — a human on the founding team replies, usually within a business day.