Security

We take the security of our products and the health and fitness data they handle seriously. This page explains how to report a vulnerability to us, what you can expect in return, and the scope of our coordinated disclosure policy.

Reporting a vulnerability

If you believe you have found a security vulnerability in our products or services, contact us at security@reversegroup.io.

Please include, where you can: the product and version affected; a description of the issue and its potential impact; steps to reproduce or a proof of concept; and any relevant logs, screenshots or request and response captures.

Reports in English are preferred. Please do not report vulnerabilities through public channels, social media or support chat.

What you can expect from us

  • We will acknowledge your report within 3 business days.
  • We will give an initial assessment within 10 business days.
  • We will keep you informed until the issue is resolved, at least every 30 days.
  • We will tell you when a fix has been released.
  • Where you would like to be credited, we will agree the wording with you before publishing.

We investigate every report. We may be unable to act on reports without enough information to reproduce the issue, and we may close reports describing expected behaviour or issues without realistic security impact. Where that is our conclusion, we will tell you, and why.

What we ask of you

  • Give us a reasonable opportunity to fix the issue before disclosing it publicly. We aim to agree a timeline with you; where we cannot agree, we ask for 90 days from the date of your report.
  • If you unintentionally access personal data or other confidential information, stop testing the relevant functionality, do not copy, download, retain or disclose the information, and notify us immediately. Where possible, securely delete any inadvertently obtained information and provide only the minimum evidence necessary for us to investigate. Our products process health and fitness information.
  • This policy does not authorise testing of third-party systems, services, infrastructure or accounts, even where those systems interact with or are integrated with our products.
  • Do not degrade our services: no denial-of-service testing, no automated scanning at volume, no social engineering of our staff, customers or partners, and no physical attacks.
  • Test only against accounts you own or have permission to use.

Safe harbour

If you make a good faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you in connection with it.

This policy does not authorise activity that violates applicable law, and nothing in it can bind a third party whose systems or data you access.

Scope

In scope: our product domains: reverse.health, musclecharge.app, fitover40.health; the current released versions of the RH: Fitness for Women 40+, RH: AI Weight Loss Coach, Muscle Charge and Fit Over 40 mobile applications; and the APIs serving them.

Out of scope:

  • Third-party services we use but do not operate — please report those to the provider directly.
  • Findings from automated scanners without a demonstrated exploit.
  • Missing security headers, TLS configuration or cookie flags without demonstrated impact.
  • Rate limiting on non-authentication endpoints.
  • Reports of outdated software versions without a working proof of concept.
  • Social engineering, phishing of our staff or users, and physical security.

Contact

security@reversegroup.io

Last updated: 2026-09-09