Security & Responsible Disclosure
We take the security of Rosterly and our users seriously, and we appreciate the work of security researchers who help keep it safe. If you believe you've found a vulnerability, please report it to us privately using the process below before disclosing it publicly.
How to Report
Email [email protected] with a subject line starting with "Security:". Please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it
- Any proof-of-concept code, screenshots, or requests/responses that help us verify it
- The URL(s) or feature(s) affected
Scope
In scope:
- The Rosterly web application at rosterly.pearlorientapps.com
- Authentication, session management, access control, and data-handling issues within the app
Out of scope:
- Denial-of-service attacks, spam, or load/stress testing
- Social engineering or phishing directed at our users or staff
- Physical attacks against our infrastructure or offices
- Automated vulnerability scanners run against production without prior coordination
- Issues in third-party services we integrate with but don't control
- Reports requiring physical access to a user's device, or that rely on a already-compromised account/browser
Our Commitment
- We'll acknowledge your report within 3 business days
- We'll investigate promptly and keep you updated on progress
- We'll let you know once a fix has been deployed
- With your permission, we're happy to publicly credit you for a valid, responsibly disclosed report
Responsible Disclosure Guidelines
In doing your research, please:
- Only test against your own account(s) - never access, modify, or delete other users' data
- Stop and report immediately if you encounter other users' personal data
- Give us a reasonable time to investigate and fix an issue (we ask for 90 days) before any public disclosure
- Make a good-faith effort to avoid privacy violations and service disruption
Safe Harbor
We won't pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy. This includes accessing only the minimum amount of data necessary to demonstrate an issue.