FeaturesPricingAboutContact

Vulnerability Disclosure Policy

If you've found a genuine security issue in Redline, we want to hear about it — and we'll treat you fairly for telling us.

How to report

Email [email protected] with what you found, the steps to reproduce it, and why you believe it's a real security issue. A real person reads every message here — this address exists for exactly this, separate from general enquiries.

What we ask

Please give us a reasonable chance to investigate and fix a genuine issue before disclosing it publicly. Don't access, modify, or delete data that isn't yours while testing — a description of the issue (or testing against your own account) is enough to prove it's real. Don't run automated scanning that could degrade the service for real brokerages using it.

What you can expect from us

A real reply from a real person, not an autoresponder loop. We'll work with you in good faith to understand and fix a genuine report, and we won't pursue legal action against a good-faith researcher who follows this policy. We can't promise a bounty — Redline is a small, independently-run product with no paid bug-bounty program today — but we will credit you (if you want that) once a real issue is fixed.

See the full Security & trust page for everything else we do to protect your data.

Get started free