Security & Vulnerability Reporting
We value the security community's efforts in helping us keep our platform secure
Our Commitment to Security
At Recap Innovations, we take the security and privacy of our users' data seriously. We appreciate the security research community's role in helping us maintain the highest security standards for our platform.
This page outlines our responsible disclosure policy and provides guidance for security researchers who wish to report vulnerabilities they discover in our systems.
We are committed to working with researchers to verify and address any legitimate security issues promptly and transparently.
Scope
What's covered by our security program
✓ In Scope
- recap-innovations.com and all subdomains
- Recap API endpoints
- LMS integrations (Canvas, Brightspace, Blackboard)
- Video player and accessibility features
- Authentication and authorization systems
- Data handling and storage mechanisms
- Caption converter and processing tools
✗ Out of Scope
- Social engineering attacks (phishing, etc.)
- Denial of Service (DoS/DDoS) attacks
- Physical security testing
- Attacks requiring physical access to user devices
- Third-party services we integrate with
- Vulnerabilities in outdated browsers or operating systems
- Reports from automated tools without validation
- Issues already reported or publicly known
High Priority Vulnerabilities
We are particularly interested in reports of:
- Remote code execution (RCE)
- SQL injection, NoSQL injection, or other injection attacks
- Authentication or authorization bypass
- Cross-site scripting (XSS) leading to account compromise
- Insecure direct object references (IDOR) exposing sensitive data
- Server-side request forgery (SSRF)
- Security misconfigurations that expose sensitive data
- Broken access controls allowing unauthorized data access
- Cross-site request forgery (CSRF) on sensitive operations
How to Report a Vulnerability
Reporting Process
Please report security vulnerabilities via email to:
For sensitive reports, you may encrypt your message using our PGP key (available upon request).
What to Include in Your Report
To help us understand and reproduce the issue, please include:
- Vulnerability description: Clear explanation of the security issue
- Affected systems: URLs, endpoints, or components affected
- Steps to reproduce: Detailed, step-by-step instructions
- Proof of concept: Code, screenshots, or videos demonstrating the issue
- Impact assessment: Your analysis of the potential security impact
- Remediation suggestions: Any recommendations for fixing the issue (optional)
- Your contact information: How we can reach you for follow-up
What to Expect
Our Response Timeline
We will acknowledge receipt of your report within 2 business days.
We will validate the issue and determine its severity within 5 business days.
We will provide updates when the issue is resolved.
Timeline for resolution depends on severity. Critical issues will be prioritized and addressed as quickly as possible, typically within 30 days. Lower severity issues may take longer to address based on our development roadmap.
Recognition
We believe in recognizing security researchers who help us improve our security posture. With your permission, we will:
- Acknowledge your contribution in our security acknowledgments page (if you wish to be named)
- Provide a reference letter for verified, high-quality reports upon request
- Work with you on coordinated disclosure timelines
Note: At this time, we do not offer a monetary bug bounty program.
Recognized Security Researchers
We thank the following researchers who have contributed to our platform's security
- Manasi Deokate
- Kamal Sharma
- Pathan Aslam
Responsible Disclosure Guidelines
What We Ask of You
To protect our users and maintain the security of our systems, we ask that you:
- Report vulnerabilities to us before disclosing them publicly
- Give us a reasonable time to address the issue before any public disclosure
- Make a good faith effort to avoid privacy violations, data destruction, and service disruption
- Only interact with accounts you own or have explicit permission to access
- Do not exploit a vulnerability beyond what is necessary to demonstrate it
- Do not access, modify, or delete data belonging to other users
- Do not perform any testing that could harm our services or users
- Do not share or distribute any vulnerabilities or sensitive data you discover
Safe Testing Practices
When testing for vulnerabilities:
- Use only test accounts that you create and own
- Do not attempt to access data of other users or organizations
- Limit your testing to the minimum necessary to demonstrate the vulnerability
- Avoid automated scanning that could impact service availability
- If you inadvertently access sensitive data, stop testing immediately and contact us
- Delete any local copies of data obtained during testing
Safe Harbor
Recap Innovations supports the safe and responsible disclosure of security vulnerabilities. We will not pursue legal action against researchers who:
- Follow these responsible disclosure guidelines
- Report vulnerabilities in good faith
- Make a good faith effort to avoid privacy violations and service disruption
- Do not exploit vulnerabilities beyond demonstrating their existence
If you follow these guidelines and act in good faith, we consider your research to be authorized under the Computer Fraud and Abuse Act and will not pursue legal action against you for your security research.
Additional Information
Security Best Practices
We follow industry-standard security practices including regular security audits, penetration testing, employee security training, and maintaining up-to-date systems and dependencies.
Data Protection
User data is encrypted at rest and in transit. We follow FERPA, GDPR, and other relevant data protection regulations. For more information, see our Privacy Policy.
Questions?
If you have questions about our security practices or this policy, please contact us at security@recap-innovations.com
Contact Our Security Team
For Security Vulnerabilities
security@recap-innovations.com
Expected response time: within 2 business days
For General Security Questions
For questions about our security practices, compliance, or security documentation for procurement:
Last updated: November 2025