We take the security of our products and the health and fitness data they handle seriously. This page explains how to report a vulnerability to us, what you can expect in return, and the scope of our coordinated disclosure policy.
Reporting a vulnerability
If you believe you have found a security vulnerability in our products or services, contact us at security@reversegroup.io.
Please include, where you can: the product and version affected; a description of the issue and its potential impact; steps to reproduce or a proof of concept; and any relevant logs, screenshots or request and response captures.
Reports in English are preferred. Please do not report vulnerabilities through public channels, social media or support chat.
What you can expect from us
We investigate every report. We may be unable to act on reports without enough information to reproduce the issue, and we may close reports describing expected behaviour or issues without realistic security impact. Where that is our conclusion, we will tell you, and why.
What we ask of you
Safe harbour
If you make a good faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you in connection with it.
This policy does not authorise activity that violates applicable law, and nothing in it can bind a third party whose systems or data you access.
Scope
In scope: our product domains: reverse.health, musclecharge.app, fitover40.health; the current released versions of the RH: Fitness for Women 40+, RH: AI Weight Loss Coach, Muscle Charge and Fit Over 40 mobile applications; and the APIs serving them.
Out of scope: