Security at Prediko

Reporting a vulnerability

‍

We welcome reports from security researchers and customers.

  • Contact: security@prediko.io (routes directly to our backend engineering team).  
  • Acknowledgement: within 2 business days.
  • Triage decision and expected timeline: within 5 business days.  
    ‍

Please give us reasonable time to remediate before public disclosure, and do not access, modify, or exfiltrate data beyond what is needed to demonstrate the issue.  

‍

Safe harbour

We will not pursue legal action against good-faith research
that respects the guidance above.  
‍

Bug bounty

We do not currently operate a paid bug bounty programme.
‍

Remediation targets

Severity is assessed using CVSS as a guide, adjusted

for real-world exploitability in our environment.

‍

Severity Fix target
Critical (RCE, auth bypass, cross-tenant data access, leaked credentials) 3 days (immediate same-day containment)
High (privilege escalation, significant data exposure with preconditions) 7 days
Medium (limited-impact or hard-to-exploit issues) 30 days
Low (hardening, best-practice gaps) Best effort / next planned release

‍

‍