Ropely

Bug bounty

Responsible disclosure for Ropely

We welcome good-faith security research. If you find a vulnerability, report it privately before public disclosure.

In scope

  • Ropely web application and dashboard
  • Public API routes (/api/v1/*, checkout, auth, webhooks we host)
  • Authentication, authorization, and pass/access lifecycle bugs
  • Cross-tenant data leaks between creators

Out of scope

  • Third-party services (Stripe, Telegram, Paystack, creator-hosted WAHA nodes)
  • Social engineering, physical attacks, denial-of-service
  • Issues requiring unlikely user interaction without demonstrated impact
  • Scanner output without a working proof of concept

How to report

Email support@ropely.io with: description, steps to reproduce, impact assessment, and optional PoC. We aim to acknowledge within 3 business days.

Safe harbor

We will not pursue legal action against researchers who follow this policy, avoid privacy violations, do not access or modify other users' data beyond what is necessary to demonstrate the issue, and give us reasonable time to fix before public disclosure.

Rewards

We recognize valid reports with public credit (if desired) and monetary rewards where applicable:

  • Critical (auth bypass, cross-tenant data, payment/access bypass): up to $500
  • High (privilege escalation, significant info disclosure): up to $200
  • Medium / Low: acknowledgment and discretionary reward

Rewards are at our discretion based on severity and report quality. Duplicate reports share the first valid submission.

Privacy policy