EN
close
0
0 product
totalNT$ 0
Checkout
Member Login
Verify Code
Forget?
Register account

Report Vulnerability & PSIRT Policy

Security Vulnerability Reporting
Product Security

Security Vulnerability Reporting

Rapixus takes product security seriously and is committed to protecting our customers. If you discover a security vulnerability in any of our products, we encourage you to report it through the channel below. We will handle every report in accordance with our responsible disclosure principles.

Contact

Dedicated security vulnerability reporting mailbox

security@rapixus.com

This mailbox is exclusively for product security vulnerability reports and is managed by the PSIRT team.

Scope

Proprietary Software Products

All software products and services independently developed and publicly released by Rapixus

Online Service Platforms

Online services, API interfaces, and cloud platforms operated by Rapixus

Product Components

Proprietary components and core functional modules used within our products

Recommended Information to Include

Providing the following details will help the PSIRT team complete its assessment more quickly and deliver remediation or mitigation guidance sooner:
  • Server and client version numbers
  • Browser version (if applicable)
  • Devices and software required to reproduce the issue
  • Steps to reproduce the issue (screenshots or code snippets are welcome)
  • Proof-of-concept (PoC) or exploit code
  • Packet capture of the attack traffic
  • Any other relevant information

What Happens After You Report

Acknowledgement

We will confirm receipt of your report within 5 business days and assign a case number so you can track the progress of your submission.

Technical Validation & Assessment

Our engineering team will verify the vulnerability and assess the risk level using CVSS scoring to determine remediation priority. We will keep you informed throughout this stage.

Remediation & Notification

We will notify you once the fix is complete. High-severity vulnerabilities (CVSS 7.0+) will be prioritized and addressed within 14 business days; medium and low severity issues will be scheduled into regular update cycles.

Public Advisory

Depending on severity and impact, we will publish a formal security advisory and request or assist with a CVE assignment where applicable. Whistleblower information will be acknowledged or recognized for honorary contribution according to the reporter’s preference, and no additional cash rewards will be provided.

Our Commitments

Reporter Confidentiality

We will not disclose your personal information or contact details to any third party without your explicit consent.

90-Day Disclosure Principle

We commit to completing remediation and publishing an advisory within 90 days. If more time is needed, we will proactively explain the reason and work with you on a revised timeline.

Ongoing Communication

We will provide regular updates throughout the remediation process so you are always aware of the current status of your report.

Responsible Disclosure Policy

Thank you for helping us improve product security. To ensure every vulnerability is handled properly and to protect all users, please follow the guidelines below when submitting your report:
  • Please do not publicly disclose technical details or exploit information until we have completed remediation and published an advisory.
  • Where possible, please include: the affected product name and version, steps to reproduce the issue, and a description of your testing environment — this helps us investigate faster.
  • Please avoid accessing, modifying, or deleting any customer data during your research.
  • Please limit your actions to what is strictly necessary to confirm the existence of the vulnerability, and do not exploit it further.

Security Acknowledgements — Hall of Fame

We appreciate every researcher who helps make our products more secure. With your permission, we will credit your contribution in our public security advisories. Anonymous submissions are also welcome.