Disclosure
Effective Date: 31/08/2026

Security Disclosure
Last updated: 1 September 2026
Introduction
Relevent takes the security of its products, systems, and customer data seriously. We welcome responsible security research that helps us identify and address potential vulnerabilities.
This policy explains how to report a security vulnerability to Relevent, the rules that apply when conducting security research, and what you can expect from us after submitting a report.
Safe harbour
Relevent will not pursue legal action against security researchers who act in good faith and comply with this policy.
Research conducted in accordance with this policy will be considered authorised, including limited reverse engineering where strictly necessary to identify and demonstrate a vulnerability.
To remain within this safe harbour, you must:
* Only access or interact with data to the extent necessary to demonstrate the vulnerability.
* Avoid modifying, deleting, downloading, or retaining data belonging to Relevent, our customers, or other users.
* Avoid disrupting Relevent or affecting the availability of our services.
* Give us a reasonable opportunity to investigate and remediate a vulnerability before disclosing it publicly.
* Comply with all applicable laws and regulations.
This policy does not authorise activity that violates applicable law or the rights of third parties.
Testing guidelines
When conducting security research involving Relevent:
* Do not access, modify, exfiltrate, destroy, or retain customer or Relevent data.
* Do not perform denial-of-service attacks or testing that could degrade the service for other users.
* Do not conduct high-volume automated scanning that may affect platform performance.
* Do not test customer systems, accounts, stores, websites, or other environments without their explicit prior permission.
* Do not use social engineering, phishing, or physical attacks against Relevent employees, contractors, or infrastructure.
* Stop testing and contact us immediately if you encounter sensitive or personal data.
Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate it. We generally ask researchers to allow up to 90 days from the date of the initial report before disclosure.
Reporting a vulnerability
Please send security reports to security@relevent.ai.
A useful report should include:
* A clear description of the vulnerability and its potential impact.
* Step-by-step instructions for reproducing the issue.
* Relevant proof-of-concept code, screenshots, videos, or supporting material.
* The affected URL, endpoint, integration, or area of the Relevent platform.
* Any conditions required to reproduce the issue.
* Your contact details if you would like to receive updates or be publicly credited.
Reports should be submitted in English and contain enough information for us to reproduce and investigate the issue.
What to expect
After receiving a valid security report, we aim to:
* Acknowledge receipt within 5 working days.
* Provide an initial assessment and, where possible, a target remediation timeline within 10 working days.
* Keep you informed of meaningful progress while we investigate and address the issue.
* Credit you publicly for a valid report if you would like to be acknowledged.
Resolution times will vary depending on the complexity, severity, and potential impact of the vulnerability.
Bug bounty
Relevent does not currently operate a monetary bug bounty programme.
We do not guarantee financial rewards for vulnerability reports. However, we are happy to publicly acknowledge researchers who responsibly disclose valid security vulnerabilities, subject to their preference.
Severity and prioritisation
We prioritise vulnerabilities according to their severity, exploitability, and practical impact, with reference to industry-standard frameworks such as CVSS.
Issues that could result in remote code execution, authentication bypass, privilege escalation, cross-tenant access, or unauthorised access to sensitive customer data will generally receive the highest priority.
Lower-severity vulnerabilities will be assessed and addressed according to their risk and impact.
Out of scope
We generally do not accept reports relating solely to:
* Theoretical vulnerabilities without a practical or demonstrable security impact.
* Missing security headers or configuration recommendations without a demonstrated exploit path.
* Unverified output from automated vulnerability scanners.
* Social engineering or phishing attacks.
* Physical attacks against Relevent employees, offices, equipment, or infrastructure.
* Denial-of-service or resource-exhaustion testing.
* Rate-limiting or brute-force observations without a meaningful security impact.
* Vulnerabilities in third-party products or services that are outside Relevent’s control.
If you are unsure whether an issue falls within scope, you are welcome to contact us before conducting further testing.
Contact
For vulnerability reports or questions about this policy, contact:
team@relevent.ai

