Vulnerability Disclosure Policy
RocketPhone takes the security of our platform and our customers' data seriously. We welcome reports from security researchers and others who believe they have found a vulnerability in our services, and we're committed to working with you to understand and resolve it quickly.
How to report
Email security@rocketphone.ai with:
- a description of the vulnerability and its potential impact;
- the affected URL, component or product;
- step-by-step instructions to reproduce it, including any proof-of-concept code, screenshots or requests;
- your contact details, if you'd like us to follow up with you.
Please report in English and send only the information needed to demonstrate the issue.
Scope
In scope:
- RocketPhone web application and administration portal
- RocketPhone APIs
- RocketPhone managed package for Salesforce;
- RocketPhone mobile applications
Out of scope:
- third-party services we use, such as Google Cloud, Salesforce or telecommunications carriers (please report these to the relevant provider);
- denial-of-service attacks or load testing;
- social engineering, phishing or physical attacks against our staff or offices;
- spam or rate-limiting issues without demonstrated security impact;
- reports from automated scanners without a demonstrated, exploitable issue;
- missing security headers or best-practice recommendations without a demonstrated security impact.
Rules of engagement
When researching vulnerabilities, please:
- only test against accounts you own or have explicit permission to use;
- not access, modify, download or delete data belonging to our customers or other users. If you encounter such data, stop, don't keep it, and tell us in your report;
- not degrade or disrupt our services or other users' experience;
- give us reasonable time to fix the issue before disclosing it publicly, and agree the disclosure timing with us.
What we commit to
When you report a vulnerability in line with this policy, we will:
- acknowledge your report within 3 working days;
- give you an initial assessment, including whether we've confirmed the issue, within 10 working days;
- keep you informed of our progress towards a fix;
- credit you for the discovery once it's resolved, if you wish.
Safe harbour
If you make a good-faith effort to comply with this policy, we will consider your research authorised. We won't take legal action against you or ask law enforcement to investigate, and if a third party takes action against you for activities that complied with this policy, we'll make it known that your actions were authorised by us.
Rewards
RocketPhone does not currently run a paid bug bounty programme and does not offer monetary rewards for reports. We genuinely appreciate the work of researchers who help keep our platform and customers safe.
