Company information
Security reporting
What to report
- Authentication, authorization, session, injection, data exposure, or cross-site scripting issues.
- Security problems in the public company website or a Polar Realm product clearly controlled by Polar Realm.
- Exposed credentials, unsafe configuration, or a plausible path to material user harm.
Report contents
Email polarrealm@gmail.com with the affected URL, product, and environment; reproduction steps and expected versus observed behavior; impact and prerequisites; and your preferred contact method and disclosure timeline. Do not include live secrets or unnecessary personal data in the first message.
Good-faith testing
Test only what is necessary to demonstrate the issue. Do not access more data than required, modify or delete user data, disrupt service, use denial-of-service techniques, send unsolicited messages, or attempt physical or social-engineering attacks.
Safe harbor
When research follows this policy, Polar Realm will treat it as authorized good-faith security research and does not intend to initiate legal action solely because of that research. This safe harbor does not authorize access to third-party systems or excuse conduct beyond the minimum needed to demonstrate a vulnerability.
Our handling
Polar Realm targets acknowledgement of a usable report within one business day and high-risk triage within two business days. We validate scope and impact, restrict access to the report, coordinate remediation, and communicate material status changes. Resolution timing depends on severity, reproducibility, affected parties, and legal obligations.
Out of scope
Automated scan output without reproducible impact, missing security headers on third-party domains, self-XSS, rate-limit observations without harm, and issues requiring compromised devices or accounts may be closed without remediation.