How to Report a Vulnerability
We encourage researchers to report vulnerabilities promptly and responsibly.
Please follow these steps:
Submit Report:
Email: vuln-disclosure@riverty.com
Include Details:
- A clear description of the vulnerability
- On which Riverty asset it was identified
- Steps to reproduce the issue
- Potential impact
Your contact information. (Note: If you choose to remain anonymous, we will be unable to update you on the progress of mitigating the vulnerability)
Use Encryption:
Fingerprint: 9E71BAE993B363DB9A5B8B6293DFD25BEA05277A
Available at: https://www.riverty.com/pgp-key.txt
Do Not Exploit:
Do not test using social engineering techniques (phishing, vishing, etc.)
Do not perform DoS or DDoS (Distributed Denial of Services) attacks.
Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary, or deleting or modifying other people's data to demonstrate the vulnerability.
Guidelines for Responsible Disclosure
To protect our customers, we ask that you:
- Report vulnerabilities privately to us before disclosing publicly.
- Allow us reasonable time to resolve the issue before public disclosure.
- Avoid accessing, downloading, or sharing sensitive customer data.
- Comply with applicable laws and regulations.
Contact
For questions about this policy or vulnerability reports, reach out to:
Email: vuln-disclosure@riverty.com