1. How to report
Email addy@rapidlabz with the subject "Security" and include the affected URL or endpoint, the steps to reproduce, and the impact you believe it has. Please report privately first and give us a reasonable chance to fix the issue before discussing it publicly.
We aim to acknowledge reports within 5 business days and to keep you updated while we investigate. We do not currently run a paid bug-bounty program.
2. In scope
Issues on the Stulla site and API, such as:
- Access to another account's events, attendees, notifications or agent keys.
- Authentication or session flaws.
- Ways to bypass agent authorization, rate limits, or the guardrails.
- Injection, stored XSS, or server-side request forgery.
3. Out of scope
Please do not report these unless you can show real impact:
- Volumetric denial of service, stress tests, or automated scanner output without a working proof of concept.
- Missing best-practice headers with no demonstrated exploit.
- Social engineering of our users, hosts, or staff.
- Vulnerabilities in third-party services we do not control.
4. Rules of engagement and safe harbor
Test only against accounts, events and agent keys you own. Do not access, modify, or retain other people's data; stop as soon as you confirm a flaw, and delete anything you incidentally received. Do not degrade the Service for other users.
If you follow these rules and report in good faith, we will treat your research as authorized, will not pursue legal action against you over it, and will work with you on a fix. Nothing here waives the rights of third parties.
Need something from us?
Email addy@rapidlabz and reference this page.