// security · v1.0 · effective 2026-05-29

Security Policy

If you found a vulnerability in REVERT itself (our API, model serving, or auth flow), please follow the disclosure path below. If you are a security researcher evaluating our practices, this document answers your questions in one read.

1. Responsible disclosure

Contact: ssolovev@revert.pro with subject prefix [Security]. PGP key on request.

We commit to:

We ask you to:

2. security.txt

Machine-readable per RFC 9116: /.well-known/security.txt

3. Our security practices

Infrastructure

Code & supply chain

Auth

4. Bug bounty hunting — data-lane separation

REVERT has both a B2B SaaS arm (this product) and an experimental bounty-hunting research arm. To prevent any conflict of interest, we maintain strict separation:

Enforcement is in code: scan-log rows are tagged with their lane, and our bounty research scripts refuse to read lane-1 rows. Audit log records every cross-lane access attempt.

5. Incident response

If we suffer a breach affecting customer data, we will:

6. No SOC 2 / ISO 27001 yet

REVERT is a solo-founder operation. We hold no formal compliance certifications. We follow security best practices but cannot satisfy procurement checklists that require third-party-audited certifications. If your procurement gates require SOC 2, please let us know — we plan to pursue it once revenue justifies the audit cost (~$30k/year for startups).

7. Acknowledgments

Researchers credited here have responsibly disclosed issues to REVERT. (List populated as disclosures arrive.)