How to report
Email [email protected] with:
- A clear description of the issue and its impact.
- Steps to reproduce (proof-of-concept, requests, screenshots where helpful).
- Affected components (web app, API, desktop client, etc.).
- Your preferred contact for follow-up (optional: PGP key if you use one).
Please give us reasonable time to fix the issue before public disclosure. Do not access data that isn't yours, degrade service for users, or pivot from research into exploitation.
What's in scope
We consider reports for:
- The Rift web and desktop applications and their interaction with our backend.
- Our APIs and authentication flows, where they are part of Rift's service.
- Infrastructure and configuration we control that materially affects customer data or service integrity (for example, misconfigured storage or TLS).
What's out of scope
We generally do not treat the following as qualifying vulnerabilities for this program:
- Issues in third-party services (for example, cloud or voice providers) unless they uniquely expose Rift's integration; please report those to the vendor when appropriate.
- Social engineering of users or staff, physical attacks, or spam.
- Self-XSS, clickjacking on non-sensitive pages, or missing security headers with no demonstrated impact.
- Denial-of-service via volumetric traffic without a clear software defect.
When in doubt, send a short note. We will tell you if it's something we track.
Response time
We aim to acknowledge valid reports within 72 hours and to keep you informed as we investigate and remediate. Critical issues may be prioritized; complex fixes can take longer. We will coordinate disclosure timelines with you when possible.
Recognition
With your permission, we thank responsible reporters in release notes or a hall of fame. We do not offer a formal bug bounty or guaranteed financial rewards at this time, but we may introduce a structured program in the future. Clear, reproducible reports make everyone safer, and we appreciate the effort.