Disclosure Policy

Disclosure Policy

Security researchers must not:

  • engage in physical testing of facilities or resources,
  • engage in social engineering,
  • send unsolicited electronic mail to RB Retail & Service Solutions users, including “phishing” messages,
  • execute or attempt to execute “Denial of Service” or “Resource Exhaustion” attacks,
  • introduce malicious software,
  • execute automated scans or tools that could disrupt services, such as password guessing attacks, or be perceived as an attack by intrusion detection/prevention systems,
  • test in a manner which could degrade the operation of RB Retail & Service Solutions systems; or intentionally impair, disrupt, or disable RB Retail & Service Solutions systems,
  • test third-party applications, websites, or services that integrate with or link to or from RB Retail & Service Solutions systems,
  • delete, alter, share, retain, or destroy RB Retail & Service Solutions data, or render RB Retail & Service Solutions data inaccessible, or, use an exploit to exfiltrate data, establish command line access, establish a persistent presence on RB Retail & Service Solutions systems, or “pivot” to other RB Retail & Service Solutions systems.

Security researchers may:

  • View or store RB Retail & Service Solutions nonpublic data only to the extent necessary to document the presence of a potential vulnerability.

Security researchers must:

  • cease testing and notify us immediately upon discovery of a vulnerability,
  • cease testing and notify us immediately upon discovery of an exposure of nonpublic data, and,
  • purge any stored RB Retail & Service Solutions nonpublic data upon reporting a vulnerability.

Thank you for helping to keep RB Retail & Service Solutions and our users safe!

© RB Retail & Service Solutions