Security

Found a vulnerability? Tell us.

We welcome reports from security researchers and anyone else who finds a problem. Email security@rudascorp.com.

Reporting a vulnerability

If you believe you have found a security problem in our website or portal, email security@rudascorp.com. Please include:

  • What the problem is and where (the page or address involved)
  • Steps to reproduce it, and what an attacker could do with it
  • Your name or handle, if you would like credit
  • Please do not include personal data you came across; describe it instead

In scope

This policy covers the services RUDAS LLC runs at:

  • rudascorp.com and www.rudascorp.com (the public site)
  • The portal and its API under rudascorp.com/dashboard and rudascorp.com/api
  • upload.rudascorp.com (large data uploads for staff)

Out of scope

Please do not test or report the following:

  • Denial of service, load or stress testing
  • Social engineering, phishing or physical attempts against our staff, tenants or partners
  • Other people's accounts or data: use only accounts and data you own
  • Services we use but do not run (for example Amazon Web Services, Cloudflare, OpenStreetMap)
  • Reports from automated scanners without a demonstrated impact
  • Missing best-practice settings with no practical way to exploit them

What we commit to

When you report in good faith and follow this policy, we will:

  • Acknowledge your report within 3 business days
  • Keep you informed while we investigate and fix it
  • Credit you once it is fixed, if you would like
  • Not pursue or support legal action against you for research that follows this policy

Good-faith research

To stay within this policy:

  • Do only what is needed to show the problem; stop and report as soon as you reach data that is not yours
  • Do not change, delete or keep anyone else's data
  • Do not disrupt the site or degrade it for others
  • Give us a reasonable time to fix the problem (normally 90 days) before telling anyone else

Other ways to reach us

If email does not reach us, use the contact form and say it is a security report; we will reply with a private channel. This policy is also published in machine-readable form at /.well-known/security.txt.

↑
Security | RUDAS LLC