Report a security vulnerability (responsible disclosure)
How to report a security issue to Reality Twin, our response timelines, and how researchers get credit.
Updated June 2, 2026 5 min read
We take security seriously and welcome responsible disclosure from independent researchers. This article covers scope, how to report, what to expect, and public credit.
How to report
- Email hello@realitytwin.io with a clear description, reproduction steps and expected impact.
- For sensitive reports, encrypt with our PGP key (available on request).
- Do not test on other customers' workspaces.
- Do not exfiltrate real data — a proof-of-concept in your own workspace is fine.
What to expect
- Acknowledgement within one business day.
- Triage and severity assessment within 3 business days.
- Remediation timeline shared within 5 business days.
- A follow-up when the fix is deployed.
- Public credit on /security with your consent.
In scope
- realitytwin.io and all *.realitytwin.io subdomains.
- The chat widget served from api/public/embed.
- The public REST API.
- The Reality Twin marketplace and profile pages.
Out of scope
- Social engineering of employees or customers.
- Physical attacks against our offices or cloud providers.
- Denial-of-service attacks against production.
- Findings that require a stolen device or a rooted phone.
- Reports from automated scanners without proof of exploitability.
Rewards
We don't run a public bounty programme yet. For severe issues we offer swag, credits, and — with permission — a public thank-you on /security.
Frequently asked questions
Do you have a security.txt?
Yes — at /.well-known/security.txt.
Can I disclose publicly after remediation?
Yes, and we encourage it. Coordinate the date with us so we can prepare a joint communication.
Related in Security & privacy
- Where is my Reality Twin data stored?Regions, sub-processors, model inference routing, encryption — everything about where your data lives.
- GDPR and Swiss FADP alignmentHow Reality Twin handles your — and your visitors' — data rights under EU GDPR and Swiss FADP, with a working data-subject request workflow.
- Sign a DPA (Data Processing Addendum) with Reality TwinGet a countersigned DPA in two business days — standard clauses, plain-language sub-processor list, SCC-backed transfers.
Did this article solve your problem?
If not, email us — a human on the founding team replies, usually within a business day.