Ryniqo OÜ · Legal Pack
Legal · Disclosure

Responsible Disclosure Policy

We welcome reports from security researchers. This Policy explains what is in scope, how to report, how quickly we respond, and the safe-harbour terms that apply to good-faith research.

Version2.0EffectiveOn publication
SupersedesGoverning lawEstonia · EU
Section 01

Scope

In scope:

  • ryniqo.com and its public subdomains.
  • The authenticated RynIQ™ Platform.
  • Public APIs operated by Ryniqo.

Out of scope:

  • Denial-of-service, volumetric or resource-exhaustion tests.
  • Physical attacks, social engineering, phishing of personnel or customers.
  • Third-party services not operated by Ryniqo (report those to the vendor).
  • Findings requiring credentials the researcher is not entitled to.
  • Missing best-practice headers without demonstrated impact.
Section 02

How to report

Send a written report to security@ryniqo.com. Please include:

  • A clear description of the issue and its impact.
  • Steps to reproduce, including URLs, payloads and timestamps.
  • Any proof-of-concept code or screenshots.
  • The version, browser and account used, if applicable.
  • Your preferred contact and whether you would like public acknowledgement.

A PGP key can be provided on request for sensitive reports.

Section 03

Response timelines

  • Acknowledgement of receipt: within 3 business days.
  • Initial triage and severity classification: within 10 business days.
  • Target remediation: Critical 30 days, High 60 days, Medium 90 days, Low 120 days.
  • Coordinated public disclosure: by mutual agreement, typically after remediation.
Section 04

Safe harbour

Ryniqo will not initiate or support legal action against a researcher for activity carried out in good faith and consistent with this Policy, including:

  • Accessing only data reasonably necessary to demonstrate the vulnerability.
  • Not intentionally degrading service.
  • Not exfiltrating data beyond what is required.
  • Deleting any Ryniqo or customer data obtained during testing on completion of the report.
  • Giving Ryniqo a reasonable opportunity to remediate before public disclosure.

Nothing in this safe harbour authorises activity in violation of applicable law.

Section 05

Acknowledgement

We publicly acknowledge researchers who make responsible reports where they consent to be named. We do not currently operate a paid bug bounty; monetary rewards are made at Ryniqo's discretion for high-impact reports.