Security
Vulnerability Disclosure Policy
Last reviewed: 2026-05-23
Our commitment
Rhino Intelligence values the security research community. We commit to working with researchers in good faith, acknowledging reports within 5 working days, and providing transparent timelines for remediation. Good-faith research conducted under this policy will not result in legal action against the researcher.
How to report
Send a report to [email protected]. Include:
- A clear description of the vulnerability
- Step-by-step reproduction (request payloads, screenshots)
- Affected URL(s) and version (commit SHA if available)
- Impact assessment (data exposure, privilege escalation, etc.)
- Suggested remediation (optional but appreciated)
PGP-encrypted reports are accepted — request the public key by email.
Scope
In scope
*.rhino-intelligence.com— all production web surfacesapi.rhino-intelligence.com— REST API endpoints- Authentication, session handling, and authorization flows
- Stripe webhook handlers + payment-link infrastructure
- GDPR data-export + account-deletion flows
- Multi-tenant data isolation — cross-organisation or cross-user data leaks are highest priority
Out of scope
- Social-engineering attacks against Rhino Intelligence staff or customers
- Denial-of-service (DoS) attacks — please do not stress-test production
- Third-party services we use (Stripe, Resend, Railway, Cloudflare, Sentry, Anthropic) — report directly to the vendor
- Best-practice deviations without a demonstrated security impact (e.g. missing security headers without a working exploit)
- Self-XSS where the attacker would need to paste code into their own browser
- Vulnerabilities requiring a rooted / jailbroken device or attacker-controlled browser extension
- Recently disclosed CVEs in dependencies we are demonstrably tracking (visible in our dependency-update PRs)
Safe harbour
Good-faith research conducted under this policy is authorised. We will not pursue legal action provided you:
- Do not access data beyond the minimum necessary to demonstrate the vulnerability
- Do not modify, destroy, or exfiltrate customer data — proof-of- concept only
- Give us a reasonable time (default 90 days) to remediate before public disclosure
- Do not engage in social engineering or denial of service
- Comply with applicable law in your jurisdiction
If you are uncertain whether a specific action falls within safe harbour, ask first via [email protected].
Our response
On receipt of a report we will:
- Acknowledge within 5 working days with a tracking reference
- Triage within 10 working days with a severity classification (CVSS 3.1) and target remediation date
- Remediate Critical/High issues within 30 days; Medium within 60 days; Low within 90 days
- Notify the reporter when the fix ships and again on full disclosure
- Credit the reporter in our public acknowledgements (unless anonymity is preferred)
Bounty
We do not currently run a paid bug-bounty programme — pre-launch resourcing constraints. A formal bounty programme is on the roadmap for SOC 2 Type II (target Q4 2026). In the meantime, researchers who report Critical / High severity issues will receive a thank-you payment via the same recognition channel.
Acknowledgements
A public list of researchers who have responsibly disclosed vulnerabilities to us is maintained at /trust (added once the first disclosure is closed-out).