If you have found something
One address, and we would rather know.
Email security@rbundle.com with what you found, where you found it, and enough detail for us to reproduce it. A short description and the steps you took is enough; you do not need a formal write-up, and you do not need to know how serious it is.
If you would like a reply, tell us how to reach you. You may report anonymously. We will not require your identity as a condition of reading or acting on your report.
We are a small team. We will acknowledge your report within five business days and tell you what we intend to do about it. We do not commit to a fix date in advance; we will agree one with you once we understand the issue. We do not pay for reports and we do not operate a bug bounty. If you would like to be credited when a fix ships, say so and we will ask you how you want to be named.
The rule that matters most here
If you can see who someone is, stop there.
Rbundle exists so that a business can ask for professional services without revealing who it is. The most serious flaw anyone could find in this product is one that connects a Request, a Bundle, a Proposal or an engagement code to the real business behind it.
If you find such a flaw, stop at the point where you can see that it works. Do not complete it. Do not read, record, screenshot, retain or transmit the identity you would be able to see, and do not attempt it a second time to check. Tell us what the path is and where it starts. We will reproduce it ourselves against our own data.
This is the one place where the usual advice — prove the impact — is the wrong advice. A demonstrated deanonymization is not a proof of harm. It is the harm.
What you may do
Your own accounts, your own data, and nothing that degrades the service.
Within the rules below, and only within them, we will treat your testing as authorised and we will not pursue you for it:
- Test against accounts and data you created yourself. If you need a second account to demonstrate a cross-account issue, create a second one of your own.
- Stop as soon as you have established that a flaw exists. Access only the minimum needed to show that.
- If you encounter another user's data, another business's identity, or anything that looks like real information about a real party, stop, do not save it, and tell us what you encountered so we can assess the exposure.
- Give us a reasonable opportunity to fix the issue before you tell anyone else about it. We will agree a disclosure date with you rather than impose one. If we go quiet, treat 90 days from your report as the point at which you are free to publish.
What you may not do
Anything that harms a user, degrades the service, or is really a different activity wearing this policy as a coat.
This policy does not authorise:
- Accessing, modifying, deleting or exfiltrating data belonging to anyone but you.
- Any attempt to identify a real Buyer, Provider or engagement, beyond the stopping point described above.
- Denial-of-service, load, stress or volumetric testing of any kind.
- Social engineering, phishing or physical intrusion against our team, our users, or our suppliers. That includes support requests made under a false pretext.
- Testing systems that are not ours. Our suppliers run their own programmes and are out of scope here.
- Automated scanning that produces volume rather than findings, and reports consisting of scanner output with no demonstrated path to impact.
- Demanding payment in exchange for withholding or disclosing a report. A report accompanied by a demand is not a disclosure and this policy does not cover it.
What is in scope
Our site and our application. Not our suppliers.
In scope: rbundle.com and its subdomains, and the Rbundle application behind them.
Out of scope: services operated by other companies that we use, including our hosting, database, authentication and email providers. If you find a flaw in one of those, report it to them; tell us too, and we will act on what we can control.
Also out of scope, because they are not flaws we can act on: missing security headers with no demonstrated exploit, weaknesses in third-party dependencies with no working path through our application, results that appear only in outdated browsers, and reports about email configuration that do not lead to a delivered spoofed message.
What we promise
The part of this page that is a commitment.
Research conducted in good faith and within the scope of this policy is authorised by Rbundle. You have our permission to access our systems to the extent this policy describes, and access within that scope is not unauthorised.
We will not bring or support a legal claim against you for research that followed this policy. If someone else brings a claim against you for such research, tell us and we will make clear that it was authorised.
If you break the rules above — particularly the ones about other people's data and other people's identities — this policy does not protect you, and none of the above applies.
We may update this policy. The version that applies to your research is the one published when you began it.