Skip to main content

Security & Vulnerability Reporting

We value the security community's efforts in helping us keep our platform secure

Our Commitment to Security

At Recap Innovations, we take the security and privacy of our users' data seriously. We appreciate the security research community's role in helping us maintain the highest security standards for our platform.

This page outlines our responsible disclosure policy and provides guidance for security researchers who wish to report vulnerabilities they discover in our systems.

We are committed to working with researchers to verify and address any legitimate security issues promptly and transparently.

Scope

What's covered by our security program

✓ In Scope

  • recap-innovations.com and all subdomains
  • Recap API endpoints
  • LMS integrations (Canvas, Brightspace, Blackboard)
  • Video player and accessibility features
  • Authentication and authorization systems
  • Data handling and storage mechanisms
  • Caption converter and processing tools

✗ Out of Scope

  • Social engineering attacks (phishing, etc.)
  • Denial of Service (DoS/DDoS) attacks
  • Physical security testing
  • Attacks requiring physical access to user devices
  • Third-party services we integrate with
  • Vulnerabilities in outdated browsers or operating systems
  • Reports from automated tools without validation
  • Issues already reported or publicly known

High Priority Vulnerabilities

We are particularly interested in reports of:

  • Remote code execution (RCE)
  • SQL injection, NoSQL injection, or other injection attacks
  • Authentication or authorization bypass
  • Cross-site scripting (XSS) leading to account compromise
  • Insecure direct object references (IDOR) exposing sensitive data
  • Server-side request forgery (SSRF)
  • Security misconfigurations that expose sensitive data
  • Broken access controls allowing unauthorized data access
  • Cross-site request forgery (CSRF) on sensitive operations

How to Report a Vulnerability

Reporting Process

Please report security vulnerabilities via email to:

For sensitive reports, you may encrypt your message using our PGP key (available upon request).

What to Include in Your Report

To help us understand and reproduce the issue, please include:

  • Vulnerability description: Clear explanation of the security issue
  • Affected systems: URLs, endpoints, or components affected
  • Steps to reproduce: Detailed, step-by-step instructions
  • Proof of concept: Code, screenshots, or videos demonstrating the issue
  • Impact assessment: Your analysis of the potential security impact
  • Remediation suggestions: Any recommendations for fixing the issue (optional)
  • Your contact information: How we can reach you for follow-up

What to Expect

Our Response Timeline

Initial Response

We will acknowledge receipt of your report within 2 business days.

Validation

We will validate the issue and determine its severity within 5 business days.

Updates

We will provide updates when the issue is resolved.

Resolution

Timeline for resolution depends on severity. Critical issues will be prioritized and addressed as quickly as possible, typically within 30 days. Lower severity issues may take longer to address based on our development roadmap.

Recognition

We believe in recognizing security researchers who help us improve our security posture. With your permission, we will:

  • Acknowledge your contribution in our security acknowledgments page (if you wish to be named)
  • Provide a reference letter for verified, high-quality reports upon request
  • Work with you on coordinated disclosure timelines

Note: At this time, we do not offer a monetary bug bounty program.

Recognized Security Researchers

We thank the following researchers who have contributed to our platform's security

  • Manasi Deokate
  • Kamal Sharma
  • Pathan Aslam

Responsible Disclosure Guidelines

What We Ask of You

To protect our users and maintain the security of our systems, we ask that you:

  • Report vulnerabilities to us before disclosing them publicly
  • Give us a reasonable time to address the issue before any public disclosure
  • Make a good faith effort to avoid privacy violations, data destruction, and service disruption
  • Only interact with accounts you own or have explicit permission to access
  • Do not exploit a vulnerability beyond what is necessary to demonstrate it
  • Do not access, modify, or delete data belonging to other users
  • Do not perform any testing that could harm our services or users
  • Do not share or distribute any vulnerabilities or sensitive data you discover

Safe Testing Practices

When testing for vulnerabilities:

  • Use only test accounts that you create and own
  • Do not attempt to access data of other users or organizations
  • Limit your testing to the minimum necessary to demonstrate the vulnerability
  • Avoid automated scanning that could impact service availability
  • If you inadvertently access sensitive data, stop testing immediately and contact us
  • Delete any local copies of data obtained during testing

Safe Harbor

Recap Innovations supports the safe and responsible disclosure of security vulnerabilities. We will not pursue legal action against researchers who:

  • Follow these responsible disclosure guidelines
  • Report vulnerabilities in good faith
  • Make a good faith effort to avoid privacy violations and service disruption
  • Do not exploit vulnerabilities beyond demonstrating their existence

If you follow these guidelines and act in good faith, we consider your research to be authorized under the Computer Fraud and Abuse Act and will not pursue legal action against you for your security research.

Additional Information

Security Best Practices

We follow industry-standard security practices including regular security audits, penetration testing, employee security training, and maintaining up-to-date systems and dependencies.

Data Protection

User data is encrypted at rest and in transit. We follow FERPA, GDPR, and other relevant data protection regulations. For more information, see our Privacy Policy.

Questions?

If you have questions about our security practices or this policy, please contact us at security@recap-innovations.com

Contact Our Security Team

For Security Vulnerabilities

security@recap-innovations.com

Expected response time: within 2 business days

For General Security Questions

For questions about our security practices, compliance, or security documentation for procurement:

sales@recap-innovations.com

Last updated: November 2025