Rendex

Security & Vulnerability Disclosure

Last updated: September 6, 2026

Rendex, operated by Copperline Labs LLC, takes the security of its screenshot and rendering API, MCP server, SDKs, and website seriously. We welcome good-faith reports from the security community. This policy explains what is in scope, how to report an issue, what you can expect from us, and the protections we extend to researchers acting in good faith.

1. How to Report

Email security@rendex.dev with a clear, reproducible report. To let us verify and fix an issue quickly, please include:

  • The affected endpoint, URL, or component;
  • A step-by-step proof of concept (requests, payloads, and expected vs. actual behavior);
  • The security impact you believe the issue has;
  • Any relevant logs, screenshots, or a short screen recording.

Our machine-readable contact details are published at /.well-known/security.txt per RFC 9116.

2. No Bug Bounty; No Compensation for Unsolicited Reports

Rendex does not operate a paid bug-bounty program and does not offer monetary rewards, gift cards, swag, or any other compensation for vulnerability reports, solicited or unsolicited. We review legitimate reports on their technical merits and will credit researchers who wish to be acknowledged (see Section 6), but no submission creates any expectation of payment. We do not respond to reports whose primary purpose is to solicit a reward, and we do not negotiate compensation in exchange for withholding or disclosing details.

3. Scope

The following are in scope:

  • rendex.dev and its subdomains (api.rendex.dev, mcp.rendex.dev);
  • The Rendex REST API and MCP server;
  • Officially published Rendex SDKs and integrations (npm, PyPI, the n8n node, and the Zapier app).

The following are out of scope:

  • Findings that require physical access to a user’s device, social engineering of our staff or users, or a compromised end-user account;
  • Denial-of-service (DoS/DDoS), volumetric, or brute-force testing;
  • Reports generated solely by automated scanners without a demonstrated, exploitable impact;
  • Missing security headers, cookie flags, SPF/DKIM/DMARC nuances, TLS-configuration preferences, or clickjacking on pages with no sensitive state or actions, absent a concrete exploit;
  • Self-XSS, best-practice suggestions, version-disclosure banners, and theoretical issues without a working proof of concept;
  • Third-party services we depend on (Cloudflare, Supabase, Stripe, Vercel, Unkey) — please report those to the respective vendor.

4. Safe Harbor

We will not pursue or support legal action against researchers who, in good faith:

  • Adhere to this policy and our Acceptable Use Policy;
  • Avoid privacy violations, data destruction, service degradation, and any access to or exfiltration of data beyond the minimum needed to demonstrate the issue;
  • Test only against accounts and resources they own or have explicit permission to test, and never against other customers’ data;
  • Give us reasonable time to remediate before any public disclosure (see Section 5).

If in doubt about whether a specific test is authorized, ask us at security@rendex.dev before you proceed.

5. Coordinated Disclosure

We ask that you keep vulnerability details confidential until we have released a fix or 90 days have elapsed from your report, whichever comes first. We are happy to coordinate a disclosure timeline and to credit your work once an issue is resolved. Please do not publicly disclose an unfixed vulnerability.

6. What to Expect From Us

  • Acknowledgement of your report within 5 business days;
  • An initial assessment of validity and severity, and an indication of next steps, where the report is actionable;
  • Progress updates for confirmed issues through to remediation;
  • Public credit, if you would like it, once the issue is fixed.

We do not publicly disclose the status of individual investigations and may decline to act on reports that fall outside the scope defined above.

7. Contact

Copperline Labs LLC
Sheridan, Wyoming, United States
Security reports: security@rendex.dev
Abuse reports: abuse@rendex.dev