Vulnerability Disclosure Program
Last updated: 24 September 2026
Found a vulnerability?
Email us at info@roleshiftin.com. Please read the rules below first: they help us protect our users, and they protect you too.
Introduction
Communication channels and ICT solutions, both hardware and software, are an integral part of RoleShiftin’s products. To ensure a high level of security and resilience across its systems, RoleShiftin runs a Vulnerability Disclosure Program (VDP) to encourage the responsible reporting of potential vulnerabilities.
RoleShiftin believes in responsible collaboration with security researchers, technology partners and third parties who share the goal of making the digital ecosystem safer.
Scope
This VDP applies exclusively to the following channels and ICT solutions:
- Web and mobile applications and cloud services developed and operated directly by RoleShiftin;
- Any other systems expressly authorised in writing by RoleShiftin.
The following are out of scope:
- Third-party systems not operated by RoleShiftin;
- Environments that are not publicly accessible, unless explicitly authorised.
Who can submit a report
A discoverer is any individual or organisation that, acting in good faith, identifies a potential vulnerability in systems within the scope of this VDP and wishes to report it responsibly to RoleShiftin.
Testing guidelines
Testing activities must follow these principles:
- Pursue security purposes only;
- Limit activities to what is strictly necessary to demonstrate that the vulnerability exists;
- Avoid any impact on the availability, integrity or confidentiality of systems.
Prohibited activities
By way of example and without limitation, the following are not permitted:
- Denial of Service attacks (DoS/DDoS);
- Accessing, modifying, deleting or exfiltrating real data, especially personal data;
- Deliberately compromising accounts that do not belong to the discoverer;
- Social engineering targeting RoleShiftin employees, customers or partners;
- Testing third-party systems or data without authorisation.
Our commitment (Safe Harbor)
RoleShiftin commits not to take legal action against discoverers who:
- Comply with this policy;
- Act in good faith;
- Limit their activities to in-scope systems;
- Avoid any harm to systems, services or data;
- Stop their activities immediately when asked to by RoleShiftin.
This commitment does not apply to malicious or negligent conduct, or to conduct that does not comply with this policy.
Responsible disclosure
RoleShiftin asks discoverers not to publicly disclose identified vulnerabilities until they have been fixed, or until the Company has given explicit written authorisation.
This is necessary because vulnerabilities may affect customers, partners and technology suppliers, and the full extent of the potential impact cannot be determined in advance.
How to report
Vulnerabilities must be reported by email to our dedicated address:
Where possible, the report should include:
- The product, service or component affected (e.g. URL, module, version);
- A clear description of the vulnerability;
- The steps used to identify it;
- Potential impact (verified or hypothesised);
- A Proof of Concept (PoC; optional);
- An email address for the discoverer (optional, but recommended so we can follow up).
How we handle reports
After a report is received:
- RoleShiftin will assess the vulnerability and, if contact details were provided and it is deemed necessary, may contact the discoverer for clarification;
- Where possible, an estimated time to resolution will be shared;
- If mitigation takes significant time, RoleShiftin may adopt temporary measures, including suspending services or features.
Structured collaboration
Should there be interest in an ongoing collaboration or in more in-depth security work, RoleShiftin and the party concerned will agree a specific contract, including an NDA.