Responsible Disclosure

Rapid Reconciliation
Responsible Disclosure Policy

Security is an important part of protecting the funders, merchants, partners, and financial information that interact with Rapid Reconciliation. Rapid welcomes responsible reports from security researchers who believe they have identified a potential vulnerability in Rapid's systems.

Reporting

Reporting a Security Issue

Security researchers should provide the following information when reporting a potential vulnerability:

Description of the potential vulnerability
Affected URL, endpoint, or service
Steps required to reproduce the issue
Supporting screenshots or evidence where appropriate
Potential impact
Researcher's preferred contact information
Guidelines

Responsible Research

Researchers participating in responsible disclosure must:

Act in good faith
Avoid accessing information beyond what is necessary to demonstrate the vulnerability
Use only accounts or systems they own or have explicit authorization to test
Avoid modifying or destroying information
Avoid disrupting Rapid's services
Protect any sensitive information accidentally encountered
Give Rapid reasonable time to investigate and address the reported issue before public disclosure
Prohibited

Prohibited Testing

Responsible disclosure does NOT authorize the following activities:

Denial-of-service or distributed denial-of-service attacks
Social engineering
Phishing
Employee or contractor impersonation
Spam
Physical security attacks
Destructive testing
Data destruction
Unauthorized access to merchant accounts
Unauthorized access to funder accounts
Unauthorized financial-account connections
Credential attacks
Testing against third-party providers outside Rapid's control
Activities prohibited by applicable law
Scope

Scope

Only Rapid-owned or Rapid-controlled systems approved for security testing are in scope.

In Scope

Rapid Reconciliation production application
Rapid-owned APIs
Rapid-owned application subdomains

Out of Scope

Plaid
MoneyThumb
Base44 infrastructure
Banking institutions
Funder systems
Merchant banking systems
Third-party APIs

These systems are controlled by third parties and are subject to their own security and disclosure policies.

Commitments

What Rapid Will Do

Rapid intends to acknowledge legitimate security reports.
Rapid intends to investigate reported vulnerabilities.
Rapid intends to communicate with the reporting researcher when additional information is required.
Rapid intends to prioritize remediation based on severity and risk.
Admin Review — No Specific SLA Without Admin Approval

Safe Harbor

Authorized security testing and potential Computer Fraud and Abuse Act implications should be reviewed by Rapid's legal counsel before any safe-harbor commitment is published.

Admin Review — Legal Review Required — Safe Harbor Determination

No Bounty Assumption

Rapid's Responsible Disclosure Policy does not create an entitlement to compensation or establish a bug bounty program.