Responsible Disclosure
Effective on public launch · Last updated: 14 July 2026
Found a security vulnerability in Roleora? Thank you — tell us, and we’ll fix it. Email security@roleora.com with steps to reproduce. We acknowledge within 48 hoursand keep you informed through the fix. Please: give us reasonable time to remediate before public disclosure, don’t access other people’s data (use your own test account), and don’t run destructive or volumetric attacks. We won’t pursue action against good-faith research within these rules. No bounty programme yet — we’re small and honest about it — but we credit researchers who want it, and career-data security reports get taken exactly as seriously as you’d hope.