Security
Responsible Disclosure
Last updated: 2026 · Crelis.ai, Singapore
We take security seriously and welcome reports from researchers acting in good faith. If you believe you’ve found a vulnerability in Crelis, please tell us before disclosing it publicly.
How to report
Email support@crelis.ai with the subject “Security disclosure”. Please include enough detail to reproduce the issue — affected URL or component, steps, and impact.
Our commitment
- We aim to acknowledge your report within two business days.
- We’ll keep you updated as we investigate and remediate.
- We will not pursue legal action against good-faith research that follows this policy.
Please do
- Give us reasonable time to fix an issue before any public disclosure.
- Avoid privacy violations, data destruction, and service disruption.
- Only test against accounts and data you own or are authorized to use.
Out of scope
Findings such as missing best-practice headers without demonstrated impact, volumetric/denial-of-service testing, and social-engineering of staff are generally out of scope.