How to report a security vulnerability in AccessPoint or the Realizer platform, and what we will do about it.
Realizer Services Inc. publishes this policy for AccessPoint and the Realizer platform. Last reviewed 2026-09-26.
AccessPoint handles access-to-information and privacy case files for government organisations. If there is a weakness in it, we would rather hear it from you than read about it later. This policy tells you what we run, what you may test, how to report what you find, what we will do, and how quickly.
We follow the coordinated vulnerability disclosure practices set out by CISA, the NSA, JPCERT/CC, NCSC-NL and NCSC-UK. We do not require non-disclosure agreements, and we do not ship silent fixes: when we fix a reported vulnerability, we say so in an advisory.
| What | Where |
|---|---|
| The Realizer platform | https://api.realizer.io — licence validation, API-address discovery, the Teams tab router, the Teams notification relay, jurisdiction pack download, the marketplace landing page and webhook, the Finish Setup page |
| The Realizer website | https://realizer.io |
| The artifact host | https://get.realizer.io |
| The container registry | realizer.azurecr.io (the AccessPoint media-worker and connector images) |
| The AccessPoint software we distribute | The API and portal packages, the SharePoint Framework package, the Teams app, the ARM/Bicep template, the deployment script, the connector packages and SDK, jurisdiction pack content |
Testing the product itself. AccessPoint is not a hosted service: it deploys into the operator's own Azure subscription and Microsoft 365 tenant. If you want to test the application rather than our platform endpoints, deploy your own instance and test that. We will help you get one running — ask at security@realizer.io. Findings from your own instance are fully in scope, including the deployment template, the database schema, the API, the portal, the web part and the worker image.
We do not limit participation by nationality, age or affiliation, and we accept anonymous reports. We may be unable to work with anyone we are legally barred from dealing with.
Tell the organisation that operates it. If you tell us instead, we will try to reach that organisation through the contacts we hold, we will not identify you to them without your permission, and we will not test their environment ourselves without their written authorisation.
We would rather you used the techniques a real attacker would use than worked around an arbitrary boundary. In exchange, stop at proof: do only as much as is necessary to demonstrate that the vulnerability exists.
If you encounter personal data, credentials, case content or anything else that is not yours, stop, do not save it, and tell us immediately. Do not access more records than you need to show the problem. Delete anything you retrieved once your report is acknowledged, and tell us that you have.
Email security@realizer.io. This mailbox is separate from customer support and is monitored for security reports only.
Encryption. If you would rather not send details by plain email, ask us for another channel and we will arrange one.
Anonymous reports are accepted. You will not be asked to identify yourself, though we cannot credit you (section 7) or tell you about the fix if we cannot reach you.
A report we can act on contains, at minimum:
An ideal report adds: a minimised proof of concept, your assessment of the impact and who is affected, a CVSS vector if you use one, any logs or timestamps of your testing (so we can tell your traffic from an attacker's), and how you would like to be credited.
Please write in English or French.
| Stage | Our target |
|---|---|
| Acknowledgement that a human has your report | 2 business days (3 at the outside) |
| Triage decision — is it valid, what severity, are we fixing it | 10 business days of acknowledgement |
| Progress updates | At least every 14 days while the report is open, without you having to ask |
| Fix or mitigation | Critical 14 days, High 30 days, Medium 90 days, Low with the next scheduled release, from the triage decision |
| Advisory published | With the release that carries the fix, or sooner if there is a mitigation you should tell people about |
| Disclosure | Coordinated with you (section 6) |
We will tell you if a target is going to slip, and why, before it slips. If we decide not to fix something, we will tell you that too, with our reasoning, and you are free to say so publicly under section 6.
Severity is assessed on the impact to the operators of AccessPoint and the people whose information it holds, not on how hard the bug was to find.
We name reporters in the advisory when they want to be named, in whatever form they ask for (name, handle, organisation, or nothing). Tell us in your report.
We do not run a paid bug bounty today. If that changes, this policy will say so before it takes effect.
If you make a good-faith effort to comply with this policy during your security research, Realizer Services Inc. will consider your research authorised, will work with you to understand and resolve the issue quickly, and will not initiate or recommend legal action against you in relation to that research. If a third party brings an action against you for activity carried out in accordance with this policy, we will make this authorisation known.
This authorisation is ours alone to give. It does not cover, and we cannot give authorisation for:
Nothing here limits the rights of any third party, and this authorisation does not override any law. If you are unsure whether something is in scope, ask us first at security@realizer.io — we would rather answer a question than read about a misunderstanding.
Our machine-readable security contact is published at /.well-known/security.txt, as RFC 9116 requires, on both realizer.io and api.realizer.io.
Published advisories are listed at /security/advisories, with an Atom feed at /security/advisories/feed.atom. There is no login and no paywall. Customers running an affected version also see the advisory inside AccessPoint, and customers who have registered a security contact receive it by email.