Rapixus takes product security seriously and is committed to protecting our customers. If you discover a security vulnerability in any of our products, we encourage you to report it through the channel below. We will handle every report in accordance with our responsible disclosure principles.
Dedicated security vulnerability reporting mailbox
security@rapixus.comThis mailbox is exclusively for product security vulnerability reports and is managed by the PSIRT team.
All software products and services independently developed and publicly released by Rapixus
Online services, API interfaces, and cloud platforms operated by Rapixus
Proprietary components and core functional modules used within our products
We will confirm receipt of your report within 5 business days and assign a case number so you can track the progress of your submission.
Our engineering team will verify the vulnerability and assess the risk level using CVSS scoring to determine remediation priority. We will keep you informed throughout this stage.
We will notify you once the fix is complete. High-severity vulnerabilities (CVSS 7.0+) will be prioritized and addressed within 14 business days; medium and low severity issues will be scheduled into regular update cycles.
Depending on severity and impact, we will publish a formal security advisory and request or assist with a CVE assignment where applicable. Whistleblower information will be acknowledged or recognized for honorary contribution according to the reporter’s preference, and no additional cash rewards will be provided.
We will not disclose your personal information or contact details to any third party without your explicit consent.
We commit to completing remediation and publishing an advisory within 90 days. If more time is needed, we will proactively explain the reason and work with you on a revised timeline.
We will provide regular updates throughout the remediation process so you are always aware of the current status of your report.
We appreciate every researcher who helps make our products more secure. With your permission, we will credit your contribution in our public security advisories. Anonymous submissions are also welcome.