Rosterly

Security & Responsible Disclosure

We take the security of Rosterly and our users seriously, and we appreciate the work of security researchers who help keep it safe. If you believe you've found a vulnerability, please report it to us privately using the process below before disclosing it publicly.

How to Report

Email [email protected] with a subject line starting with "Security:". Please include:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce it
  • Any proof-of-concept code, screenshots, or requests/responses that help us verify it
  • The URL(s) or feature(s) affected

Scope

In scope:

  • The Rosterly web application at rosterly.pearlorientapps.com
  • Authentication, session management, access control, and data-handling issues within the app

Out of scope:

  • Denial-of-service attacks, spam, or load/stress testing
  • Social engineering or phishing directed at our users or staff
  • Physical attacks against our infrastructure or offices
  • Automated vulnerability scanners run against production without prior coordination
  • Issues in third-party services we integrate with but don't control
  • Reports requiring physical access to a user's device, or that rely on a already-compromised account/browser

Our Commitment

  • We'll acknowledge your report within 3 business days
  • We'll investigate promptly and keep you updated on progress
  • We'll let you know once a fix has been deployed
  • With your permission, we're happy to publicly credit you for a valid, responsibly disclosed report

Responsible Disclosure Guidelines

In doing your research, please:

  • Only test against your own account(s) - never access, modify, or delete other users' data
  • Stop and report immediately if you encounter other users' personal data
  • Give us a reasonable time to investigate and fix an issue (we ask for 90 days) before any public disclosure
  • Make a good-faith effort to avoid privacy violations and service disruption

Safe Harbor

We won't pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy. This includes accessing only the minimum amount of data necessary to demonstrate an issue.