Skip to content
Security contact

Tell us what you found

If you believe you have found a security issue in RapidRoot, we want to hear from you directly — before anyone else does. There is no legal threat waiting at the other end of this address.

What to include

  • A description of the issue and the affected URL, endpoint or feature.
  • Steps to reproduce it, ideally with the minimum request or interaction needed.
  • The impact you believe it has — what an attacker could read, change or reach.
  • How you would like to be credited, if you would like to be.
Use a test workspace

Wherever possible, demonstrate the issue against your own workspace and your own test data.

Responsible disclosure expectations

Do not access other customers' data

If a vulnerability exposes data belonging to someone else, stop at the point of proof and tell us.

Do not degrade the service

No automated scanning that generates heavy load, no denial-of-service testing, no spam through live channels.

Give us time to fix it

Please hold public disclosure until we have had a reasonable opportunity to remediate, and coordinate timing with us.

Act in good faith

Reports made in good faith under these expectations will not be met with legal action from us.

What happens next

  1. 1

    Acknowledgement

    A human confirms we received your report.

  2. 2

    Triage

    We reproduce and assess severity based on the data and customers exposed.

  3. 3

    Remediation

    We contain, fix and verify the fix in production.

  4. 4

    Follow-up

    We close the loop with you on what changed.

No bug bounty programme

RapidRoot does not currently pay for vulnerability reports and does not run a formal bug bounty. We will still investigate every credible report and credit researchers who want credit.

Not a security issue?

For product, procurement or support questions, our team is reachable through the contact page.

Contact the team

Reports are reviewed during business hours (IST), Monday to Friday.