Skip to content
This repository has been archived by the owner on Mar 17, 2023. It is now read-only.

Latest commit

 

History

History
17 lines (11 loc) · 1.25 KB

responsible-disclosure-policy.md

File metadata and controls

17 lines (11 loc) · 1.25 KB
permalink redirect_from
/contributing/security/responsible-disclosure-policy/
/contributing/security/responsibledisclosurepolicy
/contributing/security/responsibledisclosurepolicy/

Responsible Disclosure Policy

Please submit your findings directly into our Hackerone program. Alternatively you can email the details to Rocket.Chat's security team at security@rocket.chat. You will then receive an e-mail with instruction on how to proceed with the disclosure.

Please refrain from requesting compensation for reporting vulnerabilities. If you want we will publicly acknowledge your responsible disclosure on our WhiteHat Hall of Fame. We also try to make the confidential issue public after the vulnerability is announced.

You are not allowed to search for vulnerabilities on Rocket.Chat's Community server. Rocket.Chat is open source software, you can install a copy yourself and test against that. If you want to perform testing without setting Rocket.Chat up yourself please contact us to arrange access to a staging server.

You can find more about how to contribute to our security here.