If you suspect a security vulnerability, data exposure, or other security issue with ReFresh, report it directly to the security team rather than through general support.
Report security concerns to
[email protected]Do not post security details in public forums or general support channels
Provide as much technical detail as you can
Confidentiality is respected for responsible disclosure
(Confirm internally: actual security disclosure email address and any formal vulnerability disclosure programme.)
What to report
Report any of the following:
Suspected vulnerabilities in the platform
Suspected unauthorised access to your tenant
Data exposure or leakage
Phishing or social engineering attempts that reference ReFresh
Suspicious activity on your tenant that you cannot explain
How to report
Email
[email protected]with:A short summary of the concern
Steps to reproduce, if applicable
The impact you have observed or suspect
Your contact details for follow-up
Do not include sensitive customer data in the email; ReFresh will set up a secure channel if needed
Do not post details in public forums, on social media, or in general support channels
What happens next
The security team acknowledges security reports within a defined response window and follows a structured incident response process. Specific timelines and escalation paths are shared under NDA.
Responsible disclosure
ReFresh respects responsible disclosure. If you are a security researcher, contact [email protected] to coordinate disclosure timing.
Related articles
ReFresh security overview (8.1)
Where your data is hosted (data residency) (8.2)
Contacting ReFresh support (9.7)