Report security concerns to the ReFresh security team at [email protected].
Do not post security details in public forums or general support channels.
Provide as much technical detail as you can.
Responsible disclosure is respected, and your report is handled confidentially.
What to report
Report any of the following:
Suspected vulnerabilities in the platform.
Suspected unauthorised access to your tenant.
Data exposure or leakage.
Phishing or social-engineering attempts that reference ReFresh.
Suspicious activity on your tenant that you cannot explain.
How to report
Email the security team with:
A short summary of the concern.
Steps to reproduce, if applicable.
The impact you have observed or suspect.
Your contact details for follow-up.
Do not include sensitive customer data in the email; ReFresh will set up a secure channel if it is needed.
Do not post details in public forums, on social media, or in general support channels.
What happens next
The security team acknowledges reports within a defined response window and follows a structured incident-response process. Specific timelines and escalation paths are shared under NDA.
Responsible disclosure
ReFresh supports responsible disclosure. If you are a security researcher, contact the security team to coordinate disclosure timing before making anything public.
