Security
Reporting a vulnerability
reconYa sits on networks people care about, so security reports get priority. If you think you have found a vulnerability in the reconYa app or on reconya.com, please tell us privately first.
How to report
- Email info@dyneteq.com with the subject Security.
- Include the app version (About reconYa), your operating system version, what you found, and steps or a proof of concept to reproduce it.
- We will acknowledge your report, keep you posted while we fix it, and credit you in the changelog if you want.
Please
- Give us reasonable time to ship a fix before you publish.
- Only test against your own installation and your own networks.
- Do not access other people's data, degrade the site, or run automated scanners against reconya.com.
Research done in good faith within these lines is welcome, and we will not pursue legal action over it. There is no paid bug bounty.
In scope
- The reconYa desktop app, including licence activation.
- reconya.com.
Payments and licence keys are run by Polar; issues in Polar's own systems belong with Polar's security team.
Machine-readable contact: security.txt.