Skip to content

Vulnerability disclosure

Help us keep our services secure. How to report the vulnerabilities you find, responsibly.

Effective date:

How to report

Email your findings to our security address below. Please give us reasonable time to fix the issue before disclosing it publicly.

What to include

  • The affected address, page or endpoint
  • A short description of the vulnerability and its possible impact
  • Step-by-step instructions to reproduce it
  • A screenshot or sample request, if you have one

Our commitments

  • We confirm receipt of your report as soon as we can.
  • We keep you informed while we assess and fix the issue.
  • We will not take legal action against good-faith research that follows this policy.

Research rules

  • Test only with accounts and data that belong to you.
  • Don’t access, change or delete other people’s data.
  • Avoid tests that disrupt the service (load testing, denial of service).
  • Social engineering and physical attacks are out of scope.

Reporting address

  • Security

    Send your findings to this address.

    security [at] theripplo.com