Tell us what you found
If you believe you have found a security issue in RapidRoot, we want to hear from you directly — before anyone else does. There is no legal threat waiting at the other end of this address.
What to include
- A description of the issue and the affected URL, endpoint or feature.
- Steps to reproduce it, ideally with the minimum request or interaction needed.
- The impact you believe it has — what an attacker could read, change or reach.
- How you would like to be credited, if you would like to be.
Wherever possible, demonstrate the issue against your own workspace and your own test data.
Responsible disclosure expectations
Do not access other customers' data
If a vulnerability exposes data belonging to someone else, stop at the point of proof and tell us.
Do not degrade the service
No automated scanning that generates heavy load, no denial-of-service testing, no spam through live channels.
Give us time to fix it
Please hold public disclosure until we have had a reasonable opportunity to remediate, and coordinate timing with us.
Act in good faith
Reports made in good faith under these expectations will not be met with legal action from us.
What happens next
- 1
Acknowledgement
A human confirms we received your report.
- 2
Triage
We reproduce and assess severity based on the data and customers exposed.
- 3
Remediation
We contain, fix and verify the fix in production.
- 4
Follow-up
We close the loop with you on what changed.
RapidRoot does not currently pay for vulnerability reports and does not run a formal bug bounty. We will still investigate every credible report and credit researchers who want credit.
Not a security issue?
For product, procurement or support questions, our team is reachable through the contact page.
Reports are reviewed during business hours (IST), Monday to Friday.