1. How to report
Email security@rkvault.com. A useful report tells us where the issue is (URL, endpoint, or parameter), what an attacker could do with it, and how to reproduce it step by step. Screenshots or a short proof of concept help.
Please do not include customer data, credentials, or personal information in the report beyond the minimum needed to describe the finding. Reports in English get the fastest response. You may report anonymously, though we will not be able to ask follow-up questions or credit you.
Security reports: security@rkvault.com
Scope questions: security@rkvault.com
2. Scope
In scope: the public website at rkvault.com and the subdomains we operate, including our documentation, together with the Risk Vault application as we host it.
The following are out of scope, because they are not ours to authorize testing against:
- Risk Vault deployments running in a customer-controlled environment. Contact that organization.
- Third-party services we use. Report those to the vendor, and tell us so we can follow up.
- Anything requiring physical access to our premises or equipment.
- Our staff, contractors, customers, or vendors as targets of social engineering.
Reports about missing hardening headers, unenforced best practices, or automated-scanner output with no demonstrated impact are welcome, but they are triaged after issues with a working proof of concept.
3. Authorization and safe harbor
If you make a good-faith effort to follow this policy during your research, we will consider that research authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or recommend legal action against you in connection with it. If a third party brings action against you for activity carried out in accordance with this policy, we will make it known that your research was authorized.
This authorization covers only systems we operate. It cannot and does not authorize testing against a customer’s environment, a vendor’s systems, or anyone else’s data, and it does not waive obligations you owe to others under law or contract. If you are unsure whether something is in scope, ask us first at security@rkvault.com.
4. Ground rules for testing
- Tell us as soon as you find a real or potential issue. Do not sit on it.
- Use only the access needed to demonstrate the problem, and stop once you have confirmed it.
- Do not access, modify, delete, or retain data that is not yours.
- If you encounter personal information, credentials, or customer content, stop testing immediately, do not save a copy, and say so in your report.
- Do not degrade the service for anyone else.
- Give us reasonable time to fix the issue before discussing it publicly.
5. Test methods that are not authorized
- Denial-of-service or resource-exhaustion testing.
- Physical testing of any kind.
- Social engineering or phishing of our staff, contractors, customers, or vendors.
- Brute-forcing credentials, or testing accounts you do not own.
- Deploying malware, backdoors, or any form of persistence.
- Pivoting to other systems, or extracting data beyond what a minimal proof of concept requires.
6. What you can expect from us
- We acknowledge your report within three business days.
- We give you our assessment of validity and severity within ten business days.
- While we are working on a fix, we update you at least every fifteen business days.
- We tell you when the issue is resolved, and we are glad to coordinate the timing of any write-up you want to publish.
- We credit you by name or handle if you would like to be named.
We do not currently run a paid bug-bounty program, so there is no monetary reward. What we offer is a fast, honest response and public credit where you want it.
7. If you are a Risk Vault customer
Report the finding through your usual support or security contact as well as to security@rkvault.com, so it is tracked against your agreement. Notification commitments for incidents affecting your environment are set in that agreement rather than in this policy.