REMEDiS

Security reports

This site is where you report a security problem in a product.

How it works

What you can do

  • Anyone can report You do not need an account. You get a code so you can come back and check.
  • A person here decides Someone reads your report before it becomes a case. Nothing is confirmed until they accept it.
  • Helpers stay limited Someone from another company sees only the share they were sent. That is not a staff account.

What happens after you report

  1. 1 · You send a report We keep what you write and give you a receipt code.
  2. 2 · A person sorts it They confirm what it is and how serious it is. Repeat reports can share one case.
  3. 3 · Someone owns the next step A person here tracks what happens next and the deadline.
  4. 4 · Sharing it outside A public note uses only confirmed facts. A named person has to approve sending it.

This is practice on made-up Acme work, not a real company sign-in: pick a person, look around, and reset it any time.

I'm from another company helping Invite only. Not a staff sign-in.

This opens only the share someone sent you. It is not access for people who work here.

I work here The door for a real company. Sign in with your work email.

If nobody is on the team yet, claim Owner. You copy a link. Mail is not sent. If you already work here, ask an owner for an invite, then use Get a sign-in link.

Email is not configured yet. The sign-in link appears here once. It is not sent.

Catalog bootstrap (dev)

This is not production SSO. It mints a catalog Owner or Junior token for tests and the sample desk.

Engineering owner, Fix checker, Legal, Communications, and Manager are sample people on Acme. No new password. Mail is not sent. Each person only sees the work waiting on them. The manager reads the standup.

test-dev uses a catalog session. Not production SSO.

Remedis Security · test-dev · humans decide

Reporter

File a report

You will see a receipt code on this page. Keep it. Mail is not sent unless it is configured.

Public intake for Acme. Filing does not need a sign-in.

Thank you for reporting to REMEDiS. Write what you found in plain words. A person reads it before it becomes a case.

Scope

You can report problems in the products listed below. Do not test systems you were not asked to test, do not trick people, and do not try to knock a system offline.

Safe handling

Do not include passwords, customer data, or a working attack. Describe the problem. Do not attach harmful files.

Repro details

Write the steps, the version you used, and what someone should see. Clear steps help a person understand the problem without guessing.

Attachments

This form stores your write-up. Note what you would attach. Do not upload program files here.

Disclosure

You get a receipt code and a page where you can check status and ask a question. Internal notes stay off that page. A named person decides when anything is shared outside.

After you submit

Keep the receipt code. A person reviews what you sent. You can come back with that code to ask a question.