When something fails
Every system eventually fails somewhere. What separates an institution worth trusting from one that is not is entirely in what happens in the hours afterwards.
Report anything to security@re-birth.ai. Encrypted reports are welcome; ask for the key in the first message.
- 72 hours
- 7 days
- 30 days
- 90 days
A person replies, not an autoresponder.
Severity assessed and shared with the reporter.
Resolved, or a dated plan published.
Disclosure, with credit where wanted.
Safe harbour
- Good-faith research under these terms will not be met with legal action.
- Test only against your own accounts and data.
- Do not access, modify or retain another person's data. Stop at proof.
- No denial of service, spam, social engineering or physical intrusion.
- Give us the response window above before publishing.
Current practice
- TLS everywhere. No exceptions for internal traffic.
- Encrypted storage; access to production data is logged and attributable.
- Row-level authorisation on every public table; least privilege by default.
- Held in managed secret storage, never in the codebase, rotated on personnel change.
- Automated scanning; known-vulnerable dependencies block a release.
- Point-in-time recovery, restore tested rather than assumed.
Incidents
None to report. When there is one, it appears here and in the Journal with what failed, who was affected, what changed, and the timeline — not a paragraph written to minimise it.