Range Responsible Disclosure Policy
Effective: May 16, 2017
Updated: May 16, 2018
Data security is a top priority for Range, and Range believes that working with skilled security researchers can identify weaknesses in any technology.
If you believe you’ve found a security vulnerability in Range’s service, please notify us; we will work with you to resolve the issue promptly.
Disclosure policy
- Let us know as soon as possible when you’ve discovered a potential vulnerability by emailing us at security@range.co. We vow to acknowledge your email within 24 hours.
- Provide us a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within one day of disclosure.
- Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Range service. Please only interact with domains you own or for which you have explicit permission from the account holder.
Exclusions
While researching, we’d like you to refrain from:
- Denial of service
- Spamming
- Social engineering or phishing of Range employees or contractors
- Any attacks against Range’s physical property or data centers
Thank you for helping to keep Range and our users safe!
Changes to these guidelines
We may revise these guidelines from time to time. The most current version of the guidelines will be available at https://policy.range.co/disclosure.html.
Contact
Range is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to email us at support@range.co.