Skip to main content

Reporting a security concern

If you suspect a security vulnerability, data exposure, or other security issue with ReFresh, report it directly to the security team rather than through general support.

Written by Taylor Laing
  • Report security concerns to the ReFresh security team at [email protected].

  • Do not post security details in public forums or general support channels.

  • Provide as much technical detail as you can.

  • Responsible disclosure is respected, and your report is handled confidentially.

What to report

Report any of the following:

  • Suspected vulnerabilities in the platform.

  • Suspected unauthorised access to your tenant.

  • Data exposure or leakage.

  • Phishing or social-engineering attempts that reference ReFresh.

  • Suspicious activity on your tenant that you cannot explain.

How to report

  1. Email the security team with:

    • A short summary of the concern.

    • Steps to reproduce, if applicable.

    • The impact you have observed or suspect.

    • Your contact details for follow-up.

  2. Do not include sensitive customer data in the email; ReFresh will set up a secure channel if it is needed.

  3. Do not post details in public forums, on social media, or in general support channels.

What happens next

The security team acknowledges reports within a defined response window and follows a structured incident-response process. Specific timelines and escalation paths are shared under NDA.

Responsible disclosure

ReFresh supports responsible disclosure. If you are a security researcher, contact the security team to coordinate disclosure timing before making anything public.

Did this answer your question?