Rollbar aims to keep its Services safe for everyone, and data security is of utmost priority. If you are a security researcher and have discovered a security vulnerability in the Services, we appreciate your help in disclosing it to us in a responsible manner.
Rollbar will engage with security researchers when vulnerabilities are reported to us in accordance with this Responsible Disclosure Policy. We will validate, respond and fix vulnerabilities in accordance with our commitment to security and privacy. We won't take legal action against or suspend or terminate access to the Services of those who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy. Rollbar reserves all of its legal rights in the event of any noncompliance.
Capitalized terms used in this Responsible Disclosure Policy and not otherwise defined have the meaning ascribed to such terms in our Terms of Service.
Testing
You may test only against an Account for which you are the Account owner or a Member authorized by the Account owner to conduct such testing. In no event are you permitted to access, download or modify data residing in any other Account or that does not belong to you or attempt to do any of the foregoing. You are also prohibited from:
executing or attempting to execute any "Denial of Service" attack;
knowingly posting transmitting, uploading, linking to, sending or storing any Malicious Software;
testing in a manner that would result in the sending unsolicited or unauthorized junk mail, spam, pyramid schemes or other forms of duplicative or unsolicited messages;
testing in a manner that would degrade the operation of the Services;
testing third party applications or websites or services that integrate with or link to the Services.
Reporting
Share the details of any suspected vulnerabilities with the Rollbar Security Team by sending an email to [email protected]. Please do not publicly disclose these details without express written consent from Rollbar. In reporting any suspected vulnerabilities, please include the following information:
Vulnerability details with information to allow us to efficiently reproduce your steps
Your email address
Your name as it should be displayed on this page if you would like it to be
Your Twitter handle or website as it should be displayed
Compensation Requests
Requests for monetary compensation in connection with any identified or alleged vulnerability will be deemed noncompliant with this Responsible Disclosure Policy.
Our Commitment
If you identify a verified security vulnerability in compliance with this Responsible Disclosure Policy, Rollbar commits to:
Promptly acknowledge receipt of your vulnerability report
Provide an estimated timetable for resolution of the vulnerability
Notify you when the vulnerability is fixed
Publicly acknowledge your responsible disclosure
Contributors
Rollbar thanks the following individuals and organizations that have identified security vulnerabilities in accordance with this Responsible Disclosure Policy:
Rollbar aims to keep its Services safe for everyone, and data security is of utmost priority. If you are a security researcher and have discovered a security vulnerability in the Services, we appreciate your help in disclosing it to us in a responsible manner.
\n
Rollbar will engage with security researchers when vulnerabilities are reported to us in accordance with this Responsible Disclosure Policy. We will validate, respond and fix vulnerabilities in accordance with our commitment to security and privacy. We won't take legal action against or suspend or terminate access to the Services of those who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy. Rollbar reserves all of its legal rights in the event of any noncompliance.
\n
Capitalized terms used in this Responsible Disclosure Policy and not otherwise defined have the meaning ascribed to such terms in our Terms of Service.
\n
Testing
\n
You may test only against an Account for which you are the Account owner or a Member authorized by the Account owner to conduct such testing. In no event are you permitted to access, download or modify data residing in any other Account or that does not belong to you or attempt to do any of the foregoing. You are also prohibited from:
\n
\n
executing or attempting to execute any "Denial of Service" attack;
\n
knowingly posting transmitting, uploading, linking to, sending or storing any Malicious Software;
\n
testing in a manner that would result in the sending unsolicited or unauthorized junk mail, spam, pyramid schemes or other forms of duplicative or unsolicited messages;
\n
testing in a manner that would degrade the operation of the Services;
\n
testing third party applications or websites or services that integrate with or link to the Services.
\n
\n
Reporting
\n
Share the details of any suspected vulnerabilities with the Rollbar Security Team by sending an email to security@rollbar.com. Please do not publicly disclose these details without express written consent from Rollbar. In reporting any suspected vulnerabilities, please include the following information:
\n
\n
Vulnerability details with information to allow us to efficiently reproduce your steps
\n
Your email address
\n
Your name as it should be displayed on this page if you would like it to be
\n
Your Twitter handle or website as it should be displayed
\n
\n
Compensation Requests
\n
Requests for monetary compensation in connection with any identified or alleged vulnerability will be deemed noncompliant with this Responsible Disclosure Policy.
\n
Our Commitment
\n
If you identify a verified security vulnerability in compliance with this Responsible Disclosure Policy, Rollbar commits to:
\n
\n
Promptly acknowledge receipt of your vulnerability report
\n
Provide an estimated timetable for resolution of the vulnerability
\n
Notify you when the vulnerability is fixed
\n
Publicly acknowledge your responsible disclosure
\n
\n
Contributors
\n
Rollbar thanks the following individuals and organizations that have identified security vulnerabilities in accordance with this Responsible Disclosure Policy:
"},"mdx":false,"opts":{"alwaysThrow":false,"compatibilityMode":false,"copyButtons":true,"correctnewlines":false,"markdownOptions":{"fences":true,"commonmark":true,"gfm":true,"ruleSpaces":false,"listItemIndent":"1","spacedTable":true,"paddedTable":true},"normalize":true,"lazyImages":true,"reusableContent":{"tags":{}},"safeMode":false,"settings":{"position":true},"theme":"light","customBlocks":{},"resourceID":"5aecc3cfdde71700037a128c","resourceType":"page","baseUrl":"/","terms":[],"variables":{"user":{},"defaults":[]}},"terms":[],"variables":{"user":{},"defaults":[]}},"doc":{"metadata":{"image":[],"title":"","description":"","keywords":"","robots":"index"},"mdx":{"altBody":"","status":"rdmd"},"api":{"results":{"codes":[{"status":200,"language":"json","code":"{}","name":""},{"status":400,"language":"json","code":"{}","name":""}]},"auth":"required","params":[],"url":"","method":"get","examples":{"codes":[]}},"next":{"pages":[],"description":""},"algolia":{"publishPending":false,"recordCount":6,"updatedAt":"2024-09-30T21:00:59.562Z","translationFailure":false},"_id":"5aecc3cfdde71700037a128c","project":"5a874ae082fdd5001282c796","version":{"pdfStatus":"","source":"readme","_id":"5a876b07d24de400828cb2fd","project":"5a874ae082fdd5001282c796","createdAt":"2018-02-16T23:36:39.997Z","releaseDate":"2018-02-16T23:36:39.997Z","categories":["5a876b07d24de400828cb2fe","5a876b08d24de400828cb2ff","5a876bcc82fdd5001282cb7c","5a876dd482fdd5001282cbc9","5a876e38ca7829001221eed7","5a876eec82fdd5001282cbcb","5a8f662968264c001f20c132","5a8f66326b00510012de6354","5a8f665f6b00510012de6356","5a8f668168264c001f20c135","5a8f669228fe2b00125ffcff","5a8f66b628fe2b00125ffd00","5a8f66bd6b00510012de6359","5a8f66d025969d0012bc6066","5a8f693228fe2b00125ffd9c","5a90738f86916d001246342a","5a9073fb86916d00124634cc","5a90743a0a654e0033505444","5a9074400a654e0033505447","5a90825f86916d0012464674","5a9087cb0e4768001effa968","5a90882c3f89a0007db28867","5a9088a786916d00124647d0","5a908b8e0e4768001effaa4c","5a908dde0e4768001effaa7a","5a909eb2670276004812dbdf","5a90a2d986916d0012464cc1","5a90ae27da282100121ced2c","5a96083af8f5d70012898e10","5a981af6b2db650012329915","5a981c2af5fcaa0012144047","5aa6fed212c154001231834e","5aeb60063566c8000349b694","5aecbfbfa4c4a200035958bd","5e04c66822bb70006bea3964","5e04ec186c2c3d005d59a743","5e14f0a9f303bb0018c74ac4","6192be6557fe57000f5aaba8","62dca6181f36f8002e0baccb","62de9e06fd51710021a7e872","62de9e1b6316c304034d006b","62dea06d88d21700a1234a48","6376b422081e400003bac42f"],"is_deprecated":false,"is_hidden":false,"is_beta":false,"is_stable":true,"codename":"","version_clean":"1.0.0","version":"1.0.0","__v":35,"apiRegistries":[]},"category":{"_id":"5aecbfbfa4c4a200035958bd","project":"5a874ae082fdd5001282c796","version":"5a876b07d24de400828cb2fd","isAPI":false,"reference":false,"createdAt":"2018-05-04T20:17:03.349Z","from_sync":false,"order":20,"slug":"legal","title":"Policy and Legal","__v":0,"type":"guide","id":"5aecbfbfa4c4a200035958bd"},"user":"5ef111a15db4ba004f15f69c","updates":["5ff35a3da2f9be01a8067c95","6047f4123cce5200189f221d","6050ac9a237d46006811a323","60648846b21680004bb41844","60c0e4c67c5fb601eed11032","6100723a3bb15e00163a49ed","610195f12dccbd02c7886700","611cc250aed24f004351f71b","62010ad35d32ed051429c222","62013e7bf5af860204816485","62162f15cc1b88002a896d16","6291343688c18600469a0310","62acbf4dada9fd0047cc6000","62cc9a6c184a5300a3d18a7e","62cd732e7c9d88003b25f6e6","62d0871459c3bc002e6e67dd","62d09c64632009004b9deefa","62d1b2df10703f00606b1b8a","62d1c388aafa0e002e9fffda","62d56ab06f137d020f3bc824","62d587912c319609b468df02","62d6cc0b59caf901bcde2743","62d9b78e85488b00142793e7","62d9c764cc702f00275251d4","62e2de5ccc4ed10342a299e8","630cd63c8251140021997c8b","630e7372d31798007012312c","630f74a39930a100926bf2ff","6324cd5d20abe20022bd4129","6328adb1b5aae5001098934a","632b5cbce4d23e00689a6bfe","6331c127a32c25007ba6177e","6331f0be32cd440083cfb789","633459fa7332950060edcf48","6335dcd1dfbea80033cbce97","63924db08b0a5a0032ce86fc"],"createdAt":"2018-05-04T20:34:23.588Z","link_external":false,"link_url":"","githubsync":"","sync_unique":"","hidden":false,"isReference":false,"order":3,"body":"Rollbar aims to keep its Services safe for everyone, and data security is of utmost priority. If you are a security researcher and have discovered a security vulnerability in the Services, we appreciate your help in disclosing it to us in a responsible manner.\n\nRollbar will engage with security researchers when vulnerabilities are reported to us in accordance with this Responsible Disclosure Policy. We will validate, respond and fix vulnerabilities in accordance with our commitment to security and privacy. We won't take legal action against or suspend or terminate access to the Services of those who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy. Rollbar reserves all of its legal rights in the event of any noncompliance.\n\nCapitalized terms used in this Responsible Disclosure Policy and not otherwise defined have the meaning ascribed to such terms in our [Terms of Service](doc:terms-of-service).\n\n# Testing\n\nYou may test only against an Account for which you are the Account owner or a Member authorized by the Account owner to conduct such testing. In no event are you permitted to access, download or modify data residing in any other Account or that does not belong to you or attempt to do any of the foregoing. You are also prohibited from:\n\n- executing or attempting to execute any \"Denial of Service\" attack;\n- knowingly posting transmitting, uploading, linking to, sending or storing any Malicious Software;\n- testing in a manner that would result in the sending unsolicited or unauthorized junk mail, spam, pyramid schemes or other forms of duplicative or unsolicited messages;\n- testing in a manner that would degrade the operation of the Services;\n- testing third party applications or websites or services that integrate with or link to the Services.\n\n# Reporting\n\nShare the details of any suspected vulnerabilities with the Rollbar Security Team by sending an email to [security@rollbar.com](mailto:security@rollbar.com). Please do not publicly disclose these details without express written consent from Rollbar. In reporting any suspected vulnerabilities, please include the following information:\n\n- Vulnerability details with information to allow us to efficiently reproduce your steps\n- Your email address\n- Your name as it should be displayed on this page if you would like it to be\n- Your Twitter handle or website as it should be displayed\n\n# Compensation Requests\n\nRequests for monetary compensation in connection with any identified or alleged vulnerability will be deemed noncompliant with this Responsible Disclosure Policy.\n\n# Our Commitment\n\nIf you identify a verified security vulnerability in compliance with this Responsible Disclosure Policy, Rollbar commits to:\n\n- Promptly acknowledge receipt of your vulnerability report\n- Provide an estimated timetable for resolution of the vulnerability\n- Notify you when the vulnerability is fixed\n- Publicly acknowledge your responsible disclosure\n\n# Contributors\n\nRollbar thanks the following individuals and organizations that have identified security vulnerabilities in accordance with this Responsible Disclosure Policy:\n\n**2024**\n\n[Sameer Shaikh](https://linkedin.com/in/sameer72/) \n[Khurram Shoaib](https://www.linkedin.com/in/syed-khurram-shoaib-89603521b/) \n[Syed Daniyal Bin Rashid](https://www.linkedin.com/in/s-daniyal/)\n\n**2023**\n\n[Sameer Shaikh](https://linkedin.com/in/sameer72/)\n\n \n\n**2022** \n[Banavath Aravind](https://www.linkedin.com/in/aravindb26) \n[Sakshi Dilip Patil](https://www.linkedin.com/in/sakshi-patil-569369188https://rollbar.zendesk.com/agent/tickets/47902) \n[Girish B O](https://www.linkedin.com/in/girish-b-o-a410bb1bb/) \n[Rahul Dhankhar](https://www.linkedin.com/in/rahul-dhankhar-412515218/) \n[Satyam Singh](https://www.linkedin.com/in/satyam-singh-893306221/) \n[Vinit Lakra](https://www.linkedin.com/in/vinithacker) \n[Aniket Kamboj](https://www.linkedin.com/in/aniket-kamboj-9b985b217/) \n[Milan Jain(Scriptkiddie)](https://www.linkedin.com/in/milan-jain-scriptkiddie-50a738213)\n\n[Kandarp Dave](https://www.linkedin.com/in/kandarp-dave-938967226)\n\n**2021** \n[Armanul miraz](https://twitter.com/mirazdevox) \n[Kirti Kharb](https://www.linkedin.com/in/kirti-kharb-29671b144) \n[Subhasis Datta](https://www.linkedin.com/in/subhasis-datta-775571160/) \n[Kartik Khurana](https://www.linkedin.com/in/kartik-khurana-878739175) \n[Muhammad Usman Nasir](https://facebook.com/leCyberzilla) \n[Ravi Kishor](https://bughunter.withgoogle.com/profile/3c96630c-9112-4ddb-a029-df2bb893c6c3) \n[Gaurang maheta](https://twitter.com/herry8833) \n[Jayalakshmi Ponnurangan](https://www.linkedin.com/in/jaya-lakshmi-697087159) \n[Mohd Asif Khan](https://www.linkedin.com/in/mohd-asif-khan-%E2%9C%AA-5228a9179/) \n[Phaneendra bhargav](https://www.linkedin.com/in/bhargavdarisa) \n[Shivani Singh](https://www.linkedin.com/in/shivani-singh-77752b190) \nKunal surya \n[Sohail Ahmed](https://www.linkedin.com/in/sohail-ahmed-755776184) \n[Harinder Singh](https://www.linkedin.com/in/lambardar) \nSachhit Anasane \n[Harshal S. Sharma](https://www.linkedin.com/in/harshalss-war10ck/) \n[Vishwash Chavda](https://www.linkedin.com/in/vishwash-chavda/)\n\n**2020** \n[Pritam Mukherjee](https://www.linkedin.com/in/pritam-mukherjee-urvil-b75ab9b9/) \nSanjeet Mishra \nVyshnav Nk \n[Foysal Ahmed Fahim](https://twitter.com/foysal1197) \n[Sohail Ahmed](https://www.linkedin.com/in/sohail-ahmed-755776184)\n\n**2019** \n[Alex Piechowski](https://piechowski.io/) \n[Ratnadip Gajbhiye](https://www.facebook.com/mr.ch4rli3) \n[Rashid](https://www.linkedin.com/in/rashid-p-6b8232189)\n\n**2018** \n[Sameer Phad](https://twitter.com/sameerphad72) \n[Mitesh Patil](https://www.linkedin.com/in/mitesh-patil-hacky55) \n[Pranshu Tiwari](https://www.linkedin.com/in/pranshu-tiwari-b5759b158) \n[Mike Jordan](mailto:mikejordan.sec@gmail.com) \n[Shameer Kashif](https://www.shellvoide.com/) \n[Rakesh Kirola](https://www.linkedin.com/in/rakesh-kirola-78857754) \n[Amal Mohandas](https://www.linkedin.com/in/amal-mohandas-8b56012a/) \n[Danish Tariq](https://www.danalweb.com/) \n[Mohammed Israil](https://twitter.com/mdisrail2468)\n\n**2017** \n[Sam Giffney](https://www.jobready.com.au/) \n[Rowan Harrison](https://www.linkedin.com/in/rowan-harrison-71972083/) \n[Mubassir Kamdar](http://www.mubassirkamdar.com/) \n[Suyog Palav](https://www.linkedin.com/in/suyog-palav) \n[Huy Kha](http://twitter.com/huykha10) \n[Zeel D. Chavda](https://www.linkedin.com/in/chavdazeel/) \n[Swapneil Kumar Dash](https://www.linkedin.com/in/swapneil-dash-7256a5b0/) \n[Muhammad Uwais](https://twitter.com/muhd_uwais_) \n[Nitesh Sharma](https://www.linkedin.com/in/niteshusharma/) \n[Shuaib Abidemi Oladigbolu](https://twitter.com/_sawzeeyy) \n[Pethuraj M](https://www.linkedin.com/in/pethu) \n[Raja Uzair Abdullah](https://www.facebook.com/RajaUzairAbdullah)\n\n**2016** \n[Deepali Malekar](https://twitter.com/cyndrela2009) \n[Guilherme Scombatti](https://twitter.com/gui_scombatti) \n[Mohammed Kaja Nawaz L J](https://twitter.com/nawazlj)\n\n**2015** \n[Pradeep Kumar](https://www.facebook.com/pradeepch99) \n[Shahmeer Amir](https://www.maadssec.com/) \n[Manjesh S](https://twitter.com/Manjesh24) \n[Manikandan Rajakumar](https://twitter.com/Mani22cars) \n[Varun Chowdary](http://www.exploitthesecurity.com/) \n[Hammad Qureshi and Huzaifa Jawaid](https://twitter.com/TheHmadQureshi) \n[Mohammad Naveed](https://www.facebook.com/Naveed.infosec) \n[Osama Ansari](https://twitter.com/AnsariOsama10) \n[Hussain Adnan Hashim](https://twitter.com/Hussain_infosec) \n[Ranjeet Singh](https://www.facebook.com/ranjeetsinghofficial) \nIndrajith.AN \n[Rafael Pablos](http://silverneox.blogspot.com/) \n[Osama Mahmood](http://osamamahmood.blogspot.com/) \nDushyant Sahu \n[Sai Shanthan Palvai](https://twitter.com/NahtnahS) \n[Kalpesh Makwana](https://www.twitter.com/makwanakalpesh2)","excerpt":"","slug":"responsible-disclosure-policy","type":"basic","title":"Responsible Disclosure Policy","__v":38,"parentDoc":null,"children":[],"updatedAt":"2024-09-30T21:00:59.570Z","pendingAlgoliaPublish":false,"previousSlug":"","slugUpdatedAt":"2020-09-11T05:23:53.858Z","deprecated":false,"icon":"","pendingTempStagingPublish":false,"revision":28,"lastUpdatedHash":"3f9ca5057bcd958a43bf849220215b15068ee1e8","reusableContent":[],"mdxAltBody":"","isApi":false,"tutorials":[],"id":"5aecc3cfdde71700037a128c"},"hideTOC":false,"meta":{"_id":"5aecc3cfdde71700037a128c","description":"Rollbar aims to keep its Services safe for everyone, and data security is of utmost priority. If you are a security researcher and have discovered a security vulnerability in the Services, we appreciate your help in disclosing it to us in a responsible manner. Rollbar will engage with security resea...","hidden":false,"image":[],"keywords":"","metaTitle":"Responsible Disclosure Policy","parent":null,"robots":"index","slug":"responsible-disclosure-policy","title":"Responsible Disclosure Policy","type":"docs"},"slugUrl":"/docs/responsible-disclosure-policy","config":{"algoliaIndex":"readme_search_v2","amplitude":{"apiKey":"dc8065a65ef83d6ad23e37aaf014fc84","enabled":true},"asset_url":"https://cdn.readme.io","domain":"readme.io","domainFull":"https://dash.readme.com","encryptedLocalStorageKey":"ekfls-2025-03-27","fullstory":{"enabled":true,"orgId":"FSV9A"},"liveblocks":{"copilotId":"co_11Q0l0JJlkcBhhAYUFh8s"},"metrics":{"billingCronEnabled":"true","dashUrl":"https://m.readme.io","defaultUrl":"https://m.readme.io","exportMaxRetries":12,"wsUrl":"wss://m.readme.io"},"proxyUrl":"https://try.readme.io","readmeRecaptchaSiteKey":"6LesVBYpAAAAAESOCHOyo2kF9SZXPVb54Nwf3i2x","releaseVersion":"5.422.0","sentry":{"dsn":"https://3bbe57a973254129bcb93e47dc0cc46f@o343074.ingest.sentry.io/2052166","enabled":true},"shMigration":{"promoVideo":"","forceWaitlist":false,"migrationPreview":false},"sslBaseDomain":"readmessl.com","sslGenerationService":"ssl.readmessl.com","stripePk":"pk_live_5103PML2qXbDukVh7GDAkQoR4NSuLqy8idd5xtdm9407XdPR6o3bo663C1ruEGhXJjpnb2YCpj8EU1UvQYanuCjtr00t1DRCf2a","superHub":{"newProjectsEnabled":true},"wootric":{"accountToken":"NPS-122b75a4","enabled":true}},"context":{"labs":{},"user":{},"terms":[],"variables":{"user":{},"defaults":[]},"project":{"_id":"5a874ae082fdd5001282c796","appearance":{"nextStepsLabel":"Learn More","hideTableOfContents":false,"showVersion":false,"html_hidelinks":false,"html_footer_meta":"","html_head":"\n\n\n\n\n","html_footer":" \n