Your data, locked down.
Operational practices
Compliance & regulation
Reporting a vulnerability
Found a security issue in Rebaar? Email [email protected] with a description, steps to reproduce, and impact. We respond within 1 business day.
See our machine-readable policy at /.well-known/security.txt.
Please DO:
- Give us reasonable time to fix before public disclosure (90 days standard)
- Provide enough detail that we can reproduce
- Use a test workspace, not a real customer's data
Please DO NOT:
- Run automated scanners against production (it trips the WAF and rate limits)
- Access, modify, or delete data that isn't yours
- Run denial-of-service tests
- Social-engineer Rebaar staff or customers
We're a bootstrapped company without a paid bug bounty — but we credit reporters publicly (with consent) and offer a free year of Growth plan for valid findings.
Acknowledgments
Log retention
Every workspace has an activity log — a complete record of who did what: sign-ins and failed sign-ins, permission and role changes, approvals, money movements, exports, and any support access by our staff. We retain it for a minimum of one year, and by default indefinitely.
A workspace Owner can set a shorter stated retention period in Settings → Data & retention, but the one-year floor always applies: breaches are typically discovered months after they occur, and a shorter window would destroy the evidence before anyone went looking. This meets India's DPDP Rules (2025) expectation for access logs and exceeds the 180 days required by the CERT-In directions of 2022. Log timestamps are recorded in UTC on clock-synchronised (NTP) infrastructure hosted in India.
Business records — invoices, tax documents and journal entries — are kept for 8 years under the Companies Act and are never removed by retention settings. Deleting a workspace is a separate, explicit action; see our privacy policy for how erasure requests are handled.
Data Protection Officer
For DPDP Act 2023 requests, data-protection complaints, or to exercise your data rights (access, correction, erasure, grievance redressal), contact:
We may appoint a separate DPO once Rebaar is classified as a Significant Data Fiduciary (SDF) under DPDP rules. Until then, the founder serves as the designated contact.