VULNERABILITY DISCLOSURE

Found a security issue? Tell us.

We welcome reports from security researchers. Here's what's in scope, how to reach us, how quickly we respond, and the commitments we make to you in return.

Last updated 7 October 2026

Scope

This policy covers realtyopspro.ai and its subdomains, including the agent dashboard, the partner marketplace, and the seller and buyer's-agent portals.

Services run by our providers are not in scope — Supabase, Vercel, PayPal, Resend, Twilio and Anthropic, among others listed on our subprocessors page. Please report issues in their platforms to them directly. If a provider's issue affects how we use it (for example, a misconfiguration on our side), that is in scope.

Out of scope

  • Denial-of-service, load testing, or anything that degrades the service for others.
  • Social engineering or phishing of our staff, customers or partners.
  • Physical attacks against offices, people or equipment.
  • Spam, or sending large volumes of email, SMS or form submissions.
  • Automated scanner output without a demonstrated, reproducible impact.
  • Missing “best-practice” headers or email-policy settings (SPF, DMARC and similar) with no practical exploit.
  • Issues that require a compromised device or an outdated, unsupported browser.

How to report

Email security@realtyopspro.ai with:

  • a description of the issue and where it is (URL, page or feature);
  • the steps to reproduce it, and any proof-of-concept;
  • what an attacker could achieve with it;
  • how we can reach you, and whether you'd like to be credited.

You may report anonymously. Please write in English.

What to expect

  • We acknowledge your report within 3 business days.
  • We confirm whether it's a valid issue, and how we plan to handle it, within 10 business days.
  • We keep you updated as we work on a fix, and tell you when it's resolved.
  • With your permission, we'll credit you once the issue is fixed.

Rules for researchers

  • Test only with accounts you own, or with the explicit permission of the account holder.
  • Never access, change, delete or keep other people's data. If you reach someone else's data by accident, stop, don't share it, and tell us in your report.
  • Do no more than is needed to show the issue exists.
  • Don't degrade the service or disrupt other users.
  • Keep the details confidential until we've fixed the issue, or until 90 days have passed since your report — whichever comes first — and give us a chance to agree a disclosure date with you.

Safe harbour

If you make a good-faith effort to follow this policy, we will consider your research authorized. We will not take legal action against you, or ask law enforcement to investigate you, for that research, and we will not hold you responsible for circumventing technical measures in the course of it.

If a third party takes legal action against you over research you did under this policy, we will make it known that your work was authorized by us. If you're unsure whether something is allowed, ask us at security@realtyopspro.ai before you go ahead.

This safe harbour applies only to our own systems. It does not cover our providers' platforms, and we cannot give permission on their behalf.

No bounty

We don't run a paid bug-bounty program, and we don't offer payment for reports. We're genuinely grateful for them all the same.