
Responsible Disclosure process and limitations
Effective date: March 05, 2026
Vulnerability Reporting
The RentSpree Security team takes security findings extremely seriously. We care deeply about the security of our products and the data that they protect. We investigate every reported security vulnerability and take action to remediate and/or mitigate all issues that we encounter.
RentSpree encourages responsible security research on our services and products. When reporting a potential vulnerability to RentSpree, please include a detailed description of the vulnerability, targets, steps, artifacts (such as web requests, responses and screen captures) in your report.
RentSpree does not accept the vulnerabilities listed below. Please review the responsible disclosure limitations before reporting vulnerabilities to us.
If you believe you’ve identified a security issue, please contact us at [email protected].
Responsible Disclosure Limitations
RentSpree does not have a formal bug bounty program and we do not currently pay for reported issues, however we welcome submissions and we take action to resolve security issues that are submitted to us in a very timely manner.
RentSpree considers some vulnerabilities as out of scope.
These include but are not limited to:
- Unvalidated LLM-generated findings
- Low Severity Clickjacking Vulnerabilities
- Missing SPF/DKIM/DMARC policies
- Display of Organization IDs during login flow
- User enumeration/brute forcing
- Automated Scans report (without an exploitable PoC)
- Content Spoofing Vulnerabilities
- Denial of Service (DoS)
- Issues present only in older versions of browsers or plugins
- Low Impact CSRF issues, including but not limited to: Login and Logout CSRF
- Missing Rate Limiting Protections (unless corresponding to authentication flow)
- Missing Security Headers and Cookie Flags, which can’t be exploited by themselves ( for example Strict-Transport-Security, HTTPOnly)
- Social engineering and phishing attacks
- Spam e-mail (missing rate limiting protections)
- TLS/SSL vulnerabilities related to configuration, version, weak ciphers (without a working exploit)
- Use of a vulnerable 3rd party library/code snippet (without providing an exploitable scenario)
- Vulnerabilities exploitable only on Unsupported and Outdated Browser, Frameworks and Platforms
- Weak password
- Any other submission assessed to be of low/no risk or impact
When using an LLM to generate reports, use this prompt:
“As a security expert who has performed thousands of web application assessments, ensure findings are valid, responses and examples fully reflect the issue it describes, and report findings with as short a description as possible including location, payload, impact, and reproduction steps. Do not provide additional analysis. ”