PropPilot

Responsible Disclosure Policy

How to report security vulnerabilities in PropPilot

Effective: 1 June 2026 | RZBB Ventures LLC

PropPilot stores sensitive landlord and tenant data including financial records, lease agreements, payment information, and personal details. We take security seriously and welcome good-faith vulnerability reports.

1. How to Report

Email: security@goproppilot.com

Include in your report: a description of the vulnerability, steps to reproduce it, the potential impact, and your contact details. We will acknowledge receipt within 2 business days.

2. What We Ask of Researchers

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption

  • Do not access, modify, or exfiltrate data belonging to other users

  • Do not conduct social engineering, spam, DDoS, or destructive testing

  • Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it (typically 90 days)

  • Provide us with reasonable time to investigate and remediate before any public disclosure

3. What We Commit To

  • Acknowledge your report within 2 business days

  • Investigate and respond with our assessment within a reasonable timeframe

  • Work with you on a responsible disclosure timeline

  • Not pursue legal action against researchers acting in good faith and in compliance with this policy

  • Credit researchers in our acknowledgements where desired

4. Scope

In scope: the PropPilot web application, API endpoints, authentication systems, and data storage.

Out of scope: third-party services (payment processor, infrastructure provider, AI provider), social engineering attacks, physical security, and denial of service testing.

5. Contact

security@goproppilot.com

Effective 1 June 2026. PropPilot is a product of RZBB Ventures LLC.