Security and Responsible Disclosure
How to report vulnerabilities and use RentAgents safely.
Report security issues privately. Do not publish active vulnerabilities or access data that is not yours.
1. Reporting
Email suspected vulnerabilities to info@rentagents.tech with the subject “Security Report”. Include affected URL or component, reproduction steps, impact, supporting evidence and safe contact details.
2. Good-faith research rules
- Use only accounts and data you own or are authorised to test.
- Do not access, modify, download or retain other users’ data.
- Do not use denial-of-service, spam, social engineering, malware or destructive testing.
- Stop immediately if personal data, credentials or secrets are exposed.
- Allow reasonable time for investigation and remediation before disclosure.
3. No automatic bounty
RentAgents does not promise a reward or bug bounty unless agreed in writing before testing.
4. Customer security duties
Customers must protect API keys, bot tokens, webhook secrets, passwords and paired devices; use least privilege; enable approvals; review logs; and revoke access promptly when staff or contractors leave.
5. Incident contact
For suspected account compromise, disable affected keys and nodes immediately and contact info@rentagents.tech.