Skip to main content

Security

Vulnerability Disclosure Policy

Last reviewed: 2026-05-23

Our commitment

Rhino Intelligence values the security research community. We commit to working with researchers in good faith, acknowledging reports within 5 working days, and providing transparent timelines for remediation. Good-faith research conducted under this policy will not result in legal action against the researcher.

How to report

Send a report to [email protected]. Include:

  • A clear description of the vulnerability
  • Step-by-step reproduction (request payloads, screenshots)
  • Affected URL(s) and version (commit SHA if available)
  • Impact assessment (data exposure, privilege escalation, etc.)
  • Suggested remediation (optional but appreciated)

PGP-encrypted reports are accepted — request the public key by email.

Scope

In scope

  • *.rhino-intelligence.com — all production web surfaces
  • api.rhino-intelligence.com — REST API endpoints
  • Authentication, session handling, and authorization flows
  • Stripe webhook handlers + payment-link infrastructure
  • GDPR data-export + account-deletion flows
  • Multi-tenant data isolation — cross-organisation or cross-user data leaks are highest priority

Out of scope

  • Social-engineering attacks against Rhino Intelligence staff or customers
  • Denial-of-service (DoS) attacks — please do not stress-test production
  • Third-party services we use (Stripe, Resend, Railway, Cloudflare, Sentry, Anthropic) — report directly to the vendor
  • Best-practice deviations without a demonstrated security impact (e.g. missing security headers without a working exploit)
  • Self-XSS where the attacker would need to paste code into their own browser
  • Vulnerabilities requiring a rooted / jailbroken device or attacker-controlled browser extension
  • Recently disclosed CVEs in dependencies we are demonstrably tracking (visible in our dependency-update PRs)

Safe harbour

Good-faith research conducted under this policy is authorised. We will not pursue legal action provided you:

  • Do not access data beyond the minimum necessary to demonstrate the vulnerability
  • Do not modify, destroy, or exfiltrate customer data — proof-of- concept only
  • Give us a reasonable time (default 90 days) to remediate before public disclosure
  • Do not engage in social engineering or denial of service
  • Comply with applicable law in your jurisdiction

If you are uncertain whether a specific action falls within safe harbour, ask first via [email protected].

Our response

On receipt of a report we will:

  1. Acknowledge within 5 working days with a tracking reference
  2. Triage within 10 working days with a severity classification (CVSS 3.1) and target remediation date
  3. Remediate Critical/High issues within 30 days; Medium within 60 days; Low within 90 days
  4. Notify the reporter when the fix ships and again on full disclosure
  5. Credit the reporter in our public acknowledgements (unless anonymity is preferred)

Bounty

We do not currently run a paid bug-bounty programme — pre-launch resourcing constraints. A formal bounty programme is on the roadmap for SOC 2 Type II (target Q4 2026). In the meantime, researchers who report Critical / High severity issues will receive a thank-you payment via the same recognition channel.

Acknowledgements

A public list of researchers who have responsibly disclosed vulnerabilities to us is maintained at /trust (added once the first disclosure is closed-out).