Vulnerability reporting
BYTELON LTD. Coordinated disclosure. No public bounty. No SLA on this page.
Email admin@bytelon.com with the affected repo or hostname (staging.renply.com / api.staging.renply.com), a short description and impact, steps or a proof of concept if you have one, and a request ID if the issue is on a live request.
Do not include customer payloads, session cookies, API keys, DSNs, or connection strings. Redact secrets. Do not file a public GitHub issue for an unpatched vulnerability. We do not run a public bug bounty. We will acknowledge reports to that inbox.
In scope: Renply staging services and Bytelon renply-* application repos. Out of scope: third-party vendor dashboards except where a Renply misconfiguration is the issue; Easybite systems; social engineering; physical security.
Same policy in git: SECURITY.md.