Our commitment
We take the security of Rendit and our users' data seriously. We work to identify and fix vulnerabilities quickly, and we welcome responsible disclosure from the security community.
Scope
The following assets are in scope for security research:
- rendit.ai — the main web application
- api.rendit.ai — the backend API
The following are out of scope:
- Denial-of-service attacks
- Social engineering of our team or users
- Physical attacks against our infrastructure
- Vulnerabilities in third-party services (report these to the vendor)
- Automated scanning without prior coordination
How to report a vulnerability
If you discover a security issue, please email support@rendit.ai with:
- A clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Any proof-of-concept code (if applicable)
Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and address it (we aim to respond within 5 business days and resolve confirmed issues within 30 days).
Our commitments to researchers
- We will acknowledge your report within 5 business days
- We will keep you informed of our progress
- We will not take legal action against researchers who follow this policy
- We will credit you in our acknowledgements (if you wish)
We currently do not offer monetary bug bounties, but we are grateful to researchers who help keep Rendit secure.
Security practices
- All data is transmitted over TLS (HTTPS)
- Passwords are hashed with bcrypt (cost factor 12)
- Authentication uses short-lived signed JWT tokens
- Database and internal services are not exposed to the public internet
- Rate limiting is applied to authentication and billing endpoints
- Stripe handles all payment card data — we never see or store card numbers
Contact
support@rendit.ai