Responsible disclosure for Ropely
We welcome good-faith security research. If you find a vulnerability, report it privately before public disclosure.
/api/v1/*, checkout, auth, webhooks we host)Email support@ropely.io with: description, steps to reproduce, impact assessment, and optional PoC. We aim to acknowledge within 3 business days.
We will not pursue legal action against researchers who follow this policy, avoid privacy violations, do not access or modify other users' data beyond what is necessary to demonstrate the issue, and give us reasonable time to fix before public disclosure.
We recognize valid reports with public credit (if desired) and monetary rewards where applicable:
Rewards are at our discretion based on severity and report quality. Duplicate reports share the first valid submission.