Responsible Disclosure Policy

Vulnerability Disclosure

At Raptor Technologies, we take security seriously. Security researchers play a vital role in keeping our platform and users safe. If you’ve found a vulnerability in our systems, we want to hear from you, and we’re committed to working with you to resolve it quickly and responsibly. This policy outlines how to report vulnerabilities responsibly, what’s in scope, and how we’ll respond.

What We Ask of You

We request that you do not:

  • Break any applicable laws or regulations
  • Access, modify, or exfiltrate real customer data
  • Access any data beyond the minimum necessary to provide a proof-of-concept
  • Exploit a vulnerability beyond the minimum necessary to confirm its existence
  • Perform denial-of-service (DoS/DDoS) or volumetric attacks of any kind
  • Perform destructive testing against our systems
  • Perform social engineering, phishing, or physical attacks against our staff or infrastructure
  • Upload, execute, or distribute any executables, malware, or harmful code to Raptor applications or systems
  • Test against accounts you don’t own or without explicit permission from account holders
  • Perform automated scanning or fuzzing without prior written approval
  • Disclose findings publicly before we’ve resolved them
  • Extort or threaten to disclose vulnerabilities in exchange for payment

Out-of-Scope

Security issues related to Raptor resources that should not be reported include:
  • Missing security headers or HTTPS best practices
  • Clickjacking on pages with no sensitive actions
  • Self-XSS or attacks that require physical device access
  • Email security issues (SPF, DKIM, DMARC) without evidence of exploitability
  • Password complexity, account lockout, or brute-force rate-limit policies
  • Outdated software versions without a working exploit
  • Automated scan output without proof of exploitability
  • Third-party services or infrastructure we don’t own or control
  • Vulnerabilities affecting only unsupported or end-of-life browsers
  • Any non-exploitable vulnerabilities or issues related to a lack of best practice

The above is in addition to the standard exclusions designated by Bugcrowd.

Submitting a Report

All vulnerability disclosures are managed through our Vulnerability Disclosure Program (VDP) on Bugcrowd. Submissions made outside of Bugcrowd may not receive a response.

By participating, you agree to act in good faith and adhere to the terms set forth by Bugcrowd in addition to the guidelines listed in Raptor’s Responsible Disclosure Policy. In return, we commit to acknowledging your report promptly, keeping you updated throughout our investigation, and not pursuing legal action for good-faith research conducted in accordance with this policy.

What to Include

  • A clear description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Screenshots, screen recordings, or a proof-of-concept where applicable
  • The affected URL, endpoint, or component