Security & Vulnerability Reports
Reconize exists to help people trust what they see. That only works if you can trust Reconize itself, so we treat every security report as a priority, and we want to hear from you.
How to reach us
Report security vulnerabilities, watermark or credential-integrity issues, or C2PA conformance concerns to:
Please include "Security" in the subject line, the version of Reconize you tested (About sheet → version number), the macOS version, steps to reproduce, and any sample files that demonstrate the issue. We will acknowledge your report within 3 business days, keep you informed as we investigate, and credit you for the discovery if you'd like.
What's in scope
- The Reconize app for macOS, including its C2PA Content Credentials signing and validation, the invisible VideoSeal pixel watermark and AudioSeal audio watermark (embedding and detection), signing-key handling and Keychain storage, and the verify pipeline.
- Integrity of signed output: anything that would let an attacker forge, transplant, or falsely validate a Reconize credential or watermark, or cause Reconize to misreport a file's provenance.
- This website (reconize.me).
Our commitments
- Good-faith research is welcome. If you make a good-faith effort to avoid privacy violations, data destruction, and service disruption while researching, we will not pursue legal action over your report.
- We fix what we confirm. Confirmed issues are remediated as quickly as is commercially reasonable, and security fixes ship free to all users.
- We report conformance issues upstream. Reconize participates in the C2PA Conformance Program. If a confirmed issue affects Reconize's conformance with the Content Credentials specification, we notify the C2PA (conformance@c2pa.org) within 72 hours of confirming it, as the program requires.
A note on what Reconize can't promise
Invisible watermarks are engineered to survive normal compression and re-encoding, but no watermark survives every possible transformation, and robustness varies with content and processing. Reports about watermark robustness limits are still valuable to us, but a watermark failing to survive an extreme transformation is a known property of the technology, not by itself a security vulnerability.
General contact
For anything that is not security-related (support, feedback, press) the same inbox works: hello@reconize.me.