Responsible Disclosure Policy
How to report security vulnerabilities in PropPilot
Effective: 1 June 2026 | RZBB Ventures LLC
PropPilot stores sensitive landlord and tenant data including financial records, lease agreements, payment information, and personal details. We take security seriously and welcome good-faith vulnerability reports.
1. How to Report
Email: security@goproppilot.com
Include in your report: a description of the vulnerability, steps to reproduce it, the potential impact, and your contact details. We will acknowledge receipt within 2 business days.
2. What We Ask of Researchers
Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
Do not access, modify, or exfiltrate data belonging to other users
Do not conduct social engineering, spam, DDoS, or destructive testing
Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it (typically 90 days)
Provide us with reasonable time to investigate and remediate before any public disclosure
3. What We Commit To
Acknowledge your report within 2 business days
Investigate and respond with our assessment within a reasonable timeframe
Work with you on a responsible disclosure timeline
Not pursue legal action against researchers acting in good faith and in compliance with this policy
Credit researchers in our acknowledgements where desired
4. Scope
In scope: the PropPilot web application, API endpoints, authentication systems, and data storage.
Out of scope: third-party services (payment processor, infrastructure provider, AI provider), social engineering attacks, physical security, and denial of service testing.
5. Contact
Effective 1 June 2026. PropPilot is a product of RZBB Ventures LLC.