Security at Prediko

Reporting a vulnerability

We welcome reports from security researchers and customers.

  • Contact: security@prediko.io (routes directly to our backend engineering team).  
  • Acknowledgement: within 2 business days.
  • Triage decision and expected timeline: within 5 business days.  

Please give us reasonable time to remediate before public disclosure, and do not access, modify, or exfiltrate data beyond what is needed to demonstrate the issue.  

Safe harbour

We will not pursue legal action against good-faith research
that respects the guidance above.  

Bug bounty

We do not currently operate a paid bug bounty programme.

Remediation targets

Severity is assessed using CVSS as a guide, adjusted

for real-world exploitability in our environment.

Severity Fix target
Critical (RCE, auth bypass, cross-tenant data access, leaked credentials) 3 days (immediate same-day containment)
High (privilege escalation, significant data exposure with preconditions) 7 days
Medium (limited-impact or hard-to-exploit issues) 30 days
Low (hardening, best-practice gaps) Best effort / next planned release