This repository hosts the public reloop.email documentation site. We apply security updates to the latest main branch only.
Do not open a public GitHub issue for security-sensitive findings.
Email reloop.sh@gmail.com with:
- A short description of the issue
- Steps to reproduce or a proof of concept
- Impact assessment (if known)
- Your preferred contact for follow-up
We will acknowledge receipt as soon as we can and work with you on a fix and disclosure timeline.
In scope for this repo:
- XSS, open redirects, or injection on reloop.email
- Misconfigured public metadata that exposes secrets
- Dependency vulnerabilities in the Next.js app that are reachable in production
Out of scope (report to the main platform if relevant):
- Reloop API, SMTP, or dashboard authentication — use the main Reloop security process / email above
- Third-party services (GitHub, hosting CDN) outside our control
- Social engineering or physical attacks
We will not pursue legal action against researchers who:
- Report in good faith
- Avoid privacy violations, data destruction, and service disruption
- Give us reasonable time to remediate before public disclosure