Skip to content
❯ RevuFlex

Legal / Security

// security policy

Responsible Disclosure

RevuFlex Ltd  ·  Company No. 17120351  ·  Registered in England & Wales
Last updated: 18 April 2026

RevuFlex Ltd welcomes reports from security researchers and users who discover potential vulnerabilities in our applications, websites, or infrastructure. We are committed to investigating all reports and addressing verified issues promptly.

How to Report a Vulnerability

If you have discovered a security vulnerability in any RevuFlex product or service, please email us with full details:

  • Primary contact: security@revuflex.com
  • Backup contact: legal@revuflex.com

Please include, where possible:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • The affected product, URL, or endpoint
  • Any proof-of-concept code, screenshots, or logs (ensure no real user data is included)
  • Your name or handle (optional) if you would like to be credited

Scope

The following are in scope for responsible disclosure:

  • Mobile applications published by RevuFlex Ltd (including One More Tile on iOS and Android)
  • Websites under the revuflex.com domain
  • Backend APIs and infrastructure we operate

Out of scope:

  • Third-party services we do not control (e.g. Supabase, AWS, Facebook, Google)
  • Issues already publicly known or in queue for remediation
  • Denial-of-service (DoS/DDoS) testing
  • Social engineering against RevuFlex personnel

Our Commitment

  • We will acknowledge your report within 5 business days
  • We will investigate and provide a resolution timeline within 30 days
  • We will credit you in our security acknowledgements (if you wish) once the issue is resolved
  • We will not pursue legal action against researchers who act in good faith and comply with this policy

Safe Harbour

Good-faith security research is welcomed. Please:

  • Do not access, modify, or destroy user data that is not your own
  • Do not disrupt service availability for other users
  • Give us a reasonable time to remediate before public disclosure
  • Comply with all applicable laws

Researchers who act in accordance with this policy will not be subject to legal action by RevuFlex Ltd.

security.txt

Machine-readable disclosure metadata (per RFC 9116) is available at:

  • https://revuflex.com/.well-known/security.txt

❯ RevuFlex

We build apps. Ours, and yours.

Legal

  • Privacy Policy
  • Terms of Service
  • Data Deletion
  • Security
  • Legal enquiries

Contact

  • hello@revuflex.com
  • security@revuflex.com
  • security.txt

RevuFlex Ltd · Registered in England & Wales · Company No. 17120351 · 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

© 2026 RevuFlex Ltd. All rights reserved.

Set in IBM Plex Sans & IBM Plex Mono, self-hosted subsets. No trackers, no analytics, no third-party requests.

> EOF