Skip to content
Polar Realm

Company information

Security reporting

Report a potential security issue privately so it can be reviewed without increasing risk.
Last updated July 12, 2026

What to report

  • Authentication, authorization, session, injection, data exposure, or cross-site scripting issues.
  • Security problems in the public company website or a Polar Realm product clearly controlled by Polar Realm.
  • Exposed credentials, unsafe configuration, or a plausible path to material user harm.

Report contents

Email polarrealm@gmail.com with the affected URL, product, and environment; reproduction steps and expected versus observed behavior; impact and prerequisites; and your preferred contact method and disclosure timeline. Do not include live secrets or unnecessary personal data in the first message.

Good-faith testing

Test only what is necessary to demonstrate the issue. Do not access more data than required, modify or delete user data, disrupt service, use denial-of-service techniques, send unsolicited messages, or attempt physical or social-engineering attacks.

Safe harbor

When research follows this policy, Polar Realm will treat it as authorized good-faith security research and does not intend to initiate legal action solely because of that research. This safe harbor does not authorize access to third-party systems or excuse conduct beyond the minimum needed to demonstrate a vulnerability.

Our handling

Polar Realm targets acknowledgement of a usable report within one business day and high-risk triage within two business days. We validate scope and impact, restrict access to the report, coordinate remediation, and communicate material status changes. Resolution timing depends on severity, reproducibility, affected parties, and legal obligations.

Out of scope

Automated scan output without reproducible impact, missing security headers on third-party domains, self-XSS, rate-limit observations without harm, and issues requiring compromised devices or accounts may be closed without remediation.