Current approach
- Traffic to the hosted service is encrypted with HTTPS.
- Passwords are stored as one-way hashes, not readable passwords.
- Account-owned resources are scoped to the authenticated account.
- API keys are shown once and stored as hashes.
- Production access is kept to the people and services that need it.
realuptime does not currently claim SOC 2, ISO 27001, PCI certification, a formal penetration test, or a security SLA. Payment details are processed by Stripe rather than stored directly by realuptime.
Report a vulnerability
Send reports to josefranco0213@gmail.com with the subject “realuptime security report.” Include the affected URL or feature, reproduction steps, likely impact, and any supporting request or response details. Do not include secrets you do not need to share.
Responsible research
When investigating a potential vulnerability:
- Use your own account and data.
- Avoid privacy violations, service disruption, social engineering, and destructive testing.
- Stop if you access another person's information and report it immediately.
- Give us a reasonable opportunity to investigate before publishing details.
This page is not a paid bug-bounty program and does not authorize testing of third-party systems, denial-of-service activity, physical attacks, or access beyond what is necessary to demonstrate a vulnerability.
What to expect
We review reports regularly and aim to acknowledge a credible report within three business days. Response and remediation time depends on severity and complexity. We will try to keep reporters informed, but this is a target rather than a contractual response-time guarantee.