Responsible Disclosure Policy
Last updated: July 24, 2026
Reporting a Vulnerability
If you believe you have found a security vulnerability affecting TaskForceOne, email [email protected] with the subject “Security Vulnerability Report”. Do not include live credentials, unnecessary personal information, or sensitive exploit data in the first email.
Please include:
- the affected domain, application, API, or feature;
- a clear description of the issue and potential impact;
- reproducible steps using your own test account and non-sensitive data;
- relevant request identifiers, timestamps, screenshots, or limited proof-of-concept material; and
- how we can contact you securely.
Research Rules
To protect customers and the service, you must:
- use only accounts and data you own or have express permission to test;
- stop immediately if you encounter another person's data and report the issue without retaining or sharing that data;
- avoid changing, deleting, downloading, or exfiltrating data;
- avoid denial-of-service, high-volume automated scanning, spam, malware, persistence, physical testing, or social engineering;
- avoid accessing employee devices, provider systems, or third-party integrations;
- give us a reasonable opportunity to investigate and remediate before public disclosure; and
- comply with applicable law and our Acceptable Use Policy.
This policy does not authorise access to data or systems beyond what is necessary for a minimal, non-destructive verification in your own account.
What We Will Do
We will acknowledge a credible report, investigate it, and keep the reporter reasonably informed of material progress where doing so does not create a security or legal risk. Remediation timing depends on severity, complexity, affected providers, and the need to protect customers.
ROVYN does not currently offer a bug bounty or promise payment, public recognition, or a particular remediation date. This policy does not authorise unlawful conduct or bind any third party.
Urgent Account or Privacy Incidents
If the issue is an exposed password, compromised account, suspected personal-information breach, or active abuse rather than a product vulnerability, contact [email protected] immediately and identify it as urgent.