Reporting an Issue
Email [email protected]. A useful report describes what you found, the steps to reproduce it, and what an attacker could do with it. Please include the date and approximate time of any requests you sent, so we can match them to our logs.
If a report contains customer data, tell us that it does rather than attaching it. We will arrange a secure way to receive it.
What You May Do Without Asking
You do not need permission to browse our public pages, read client-side JavaScript, passively observe request and response formats produced during ordinary use, or use an account you created and own as the product is intended to be used. This does not authorize vulnerability scanning, automation, attempts to bypass controls, or other active security testing. If something looks wrong, stop and tell us rather than confirming it by going further — a description of the flaw is enough for us to reproduce it ourselves.
Stop as soon as you have confirmed an issue exists. Continuing past that point — to see how much data you can reach, or how many accounts you can affect — is where good-faith research becomes an incident we have to respond to.
Disclosure
Please give us a reasonable opportunity to fix an issue before describing it publicly, and do not publish details of a vulnerability, or any data obtained through one, without our written agreement. We would rather coordinate a disclosure with you than read about it first elsewhere.
Rewards
We do not operate a bug bounty programme, and no payment is offered for a report in the absence of a written agreement signed in advance. That is not a comment on the value of the work — we simply want to be straightforward about it before you spend your time, rather than afterwards.
What to Expect From Us
We aim to acknowledge a report within five business days and to tell you what we intend to do about it. We will not pursue legal action over research conducted in good faith and within this policy, and we are happy to credit you when a fix ships if you would like us to.
This policy applies to systems Apex Rental Pro operates. It does not grant permission to test a customer’s own website, network, or third-party services that happen to be linked from a workspace.