Security & Vulnerability Disclosure
Last updated: 31 May 2026
1. Our Commitment
Run on Realms (“ROR”), operated by Mobinsons Ventures Private Limited, takes the security of our users and infrastructure seriously. We welcome and appreciate the work of security researchers who identify and responsibly disclose vulnerabilities, helping us keep the service safe for everyone.
This policy describes how to report a security issue and what you can expect in return. It is also published as a machine-readable file at /.well-known/security.txt per RFC 9116.
2. Reporting a Vulnerability
Please email [email protected] with the subject line “Security Disclosure: [brief description]”.
Include:
- A description of the vulnerability and its impact
- Steps to reproduce (with screenshots, video, or PoC code if applicable)
- The affected URL, endpoint, or app screen
- Your name and contact info (for follow-up — we can credit you publicly if you wish, or stay anonymous if you prefer)
If the vulnerability is sensitive (e.g., a credential leak, mass data exposure, or active exploitation), please use end-to-end encrypted communication. We can provide a PGP key on request.
3. What You Can Expect From Us
- Acknowledgement within 48 hours of receiving your report
- Initial triage and severity assessment within 5 business days
- Regular status updates at least every 14 days until the issue is resolved
- Credit in our security hall of fame (if you opt in) when the fix is shipped
- No legal action against good-faith researchers who follow this policy (see Safe Harbor below)
4. Safe Harbor — What's In Scope
You can test the following without fear of legal action, provided you act in good faith and follow the rules in §6 below:
- The web app at
runonrealms.comand all subdomains - The ROR mobile apps on iOS and Android
- The API at
api.runonrealms.com - The admin panel (without attempting unauthorized access to real admin accounts)
We commit to:
- Not pursuing legal action against researchers who follow this policy
- Working with you to understand and fix the issue quickly
- Treating your testing activity as authorized under applicable computer crime laws
5. Out of Scope
The following are NOT covered by Safe Harbor and may result in account termination or legal action:
- Testing against accounts you do not own, or attempting to access other users' private data
- Denial-of-service (DoS) or volumetric attacks that disrupt service for real users
- Social engineering of our employees, customers, or vendors
- Physical attacks on our offices or infrastructure
- Testing on third-party services we rely on (Razorpay, Stripe, Mapbox, AWS, etc.) — report those to the vendor directly
- Reports based purely on missing security headers without demonstrated exploitability
- Self-XSS or other issues requiring victim to perform highly unusual actions
- Spam, phishing, or any commercial / extortive activity
6. Rules of Engagement
- Use only your own accounts for testing. Don't access, modify, or delete data belonging to other users.
- Avoid causing harm. No DoS, no spam, no data destruction, no service disruption.
- Don't exfiltrate data. If you find a way to access data, stop immediately, document the proof-of-concept with minimal data, and report it.
- Don't publicly disclose the vulnerability until we've had a reasonable opportunity to fix it (typically 90 days from initial report; we will work with you on the timeline).
- Don't accept payment for silence. We do not offer monetary bug bounties at this time, but we do offer recognition and our genuine gratitude. We will never ask you to keep a vulnerability secret in exchange for compensation.
7. Severity Examples
| Severity | Examples | Target SLA |
|---|---|---|
| Critical | RCE, auth bypass, mass-PII exposure, payment manipulation | Fix < 24h |
| High | Account takeover (single user), stored XSS in admin panel, IDOR exposing private user data | Fix < 7 days |
| Medium | Reflected XSS, CSRF on sensitive action, info disclosure (non-PII) | Fix < 30 days |
| Low | Self-XSS, clickjacking on non-sensitive pages, verbose error messages | Fix < 90 days or accepted risk |
8. Contact
Security Disclosure Contact
Mobinsons Ventures Private Limited
CIN: U62011OD2026PTC053747
Email: [email protected]
Subject: Security Disclosure: [brief description]
PGP key: available on request