REDOXY · REDOXY security reporting

Report a security concern through a controlled route.

Use this route to report a suspected website, account or data-security vulnerability without exposing more information than the review requires.

Effective: 21 August 2026

REDOXY Legal & Privacy Center

Send a concise security report.

Email info@redoxyksa.com with “Security report” in the subject. Include the affected REDOXY page or function, the date observed, the impact you believe is possible and a safe way to reproduce the issue.

Do not send a password, one-time code, access token, private key, full identity document, unnecessary personal information or a copy of another person's confidential record. REDOXY may provide a safer transfer route if diagnostic evidence is required.

Focus on REDOXY-controlled website and workspace functions.

A third-party service, network, device or account controlled by someone else must be reported through that provider's own security route unless the issue is caused by REDOXY's implementation.

  • Public redoxy.co routes, forms, downloads and website APIs controlled by REDOXY.
  • Customer, administration, publishing and trading workspaces where you are authorized to test your own account.
  • Authentication, authorization, session handling, unintended public data exposure and upload or download controls.

Minimize impact while preserving useful evidence.

Use a non-destructive method and stop when you can explain the issue clearly.

  • Use only accounts, records and systems you are authorized to access.
  • Stop after obtaining the minimum evidence needed to describe the issue; do not copy, alter, delete or retain unrelated data.
  • Do not disrupt availability, send malware, conduct social engineering, overwhelm services, or test physical and safety systems.
  • Allow REDOXY a reasonable opportunity to investigate before publishing details that could increase risk.

What happens after a report.

REDOXY will review reports received through the stated contact, may ask for limited clarification, and will prioritize confirmed issues according to their likely impact. A report does not create a bug-bounty entitlement, service contract, safe-harbor promise or guaranteed response time unless REDOXY agrees otherwise in writing.

If the report also concerns personal information, REDOXY will assess it under the Privacy Policy and applicable incident-notification requirements.

Secure an account first when credentials may be exposed.

If you suspect unauthorized access to your REDOXY account, stop using the affected shared device, change the managed password through the authorized route, enable MFA where available, revoke other sessions from the Security Center, and report the concern. Never forward a live token or one-time code to prove the issue.