New guide: Your Salesforce Org Is Missing Critical Data , Download free
Security

Vulnerability Disclosure Policy

How to report a security issue to RocketPhone — and how we'll work with you to resolve it.

Vulnerability Disclosure Policy

RocketPhone takes the security of our platform and our customers' data seriously. We welcome reports from security researchers and others who believe they have found a vulnerability in our services, and we're committed to working with you to understand and resolve it quickly.

How to report

Email security@rocketphone.ai with:

  • a description of the vulnerability and its potential impact;
  • the affected URL, component or product;
  • step-by-step instructions to reproduce it, including any proof-of-concept code, screenshots or requests;
  • your contact details, if you'd like us to follow up with you.

Please report in English and send only the information needed to demonstrate the issue.

Scope

In scope:

  • RocketPhone web application and administration portal
  • RocketPhone APIs
  • RocketPhone managed package for Salesforce;
  • RocketPhone mobile applications

Out of scope:

  • third-party services we use, such as Google Cloud, Salesforce or telecommunications carriers (please report these to the relevant provider);
  • denial-of-service attacks or load testing;
  • social engineering, phishing or physical attacks against our staff or offices;
  • spam or rate-limiting issues without demonstrated security impact;
  • reports from automated scanners without a demonstrated, exploitable issue;
  • missing security headers or best-practice recommendations without a demonstrated security impact.

Rules of engagement

When researching vulnerabilities, please:

  • only test against accounts you own or have explicit permission to use;
  • not access, modify, download or delete data belonging to our customers or other users. If you encounter such data, stop, don't keep it, and tell us in your report;
  • not degrade or disrupt our services or other users' experience;
  • give us reasonable time to fix the issue before disclosing it publicly, and agree the disclosure timing with us.

What we commit to

When you report a vulnerability in line with this policy, we will:

  • acknowledge your report within 3 working days;
  • give you an initial assessment, including whether we've confirmed the issue, within 10 working days;
  • keep you informed of our progress towards a fix;
  • credit you for the discovery once it's resolved, if you wish.

Safe harbour

If you make a good-faith effort to comply with this policy, we will consider your research authorised. We won't take legal action against you or ask law enforcement to investigate, and if a third party takes action against you for activities that complied with this policy, we'll make it known that your actions were authorised by us.

Rewards

RocketPhone does not currently run a paid bug bounty programme and does not offer monetary rewards for reports. We genuinely appreciate the work of researchers who help keep our platform and customers safe.