Security

Report a Security Issue.

If you've discovered a security vulnerability on rimorimo.com, we want to know about it. RIMORIMO LLC takes the security of our platform and our customers' data seriously, and we review every legitimate report we receive.

Last UpdatedJuly 22, 2026
Response TimeWithin 3 Business Days
Applies Torimorimo.com

Responsible, good-faith security research is welcome here, and we won't pursue legal action against researchers who follow the guidelines below.

Fundamentals

Responsible Disclosure Guidelines

If you follow the principles below when reporting a security issue on rimorimo.com, RIMORIMO LLC will not initiate legal action or enforcement investigations against you in response to your report. We ask that you:

  • Give us reasonable time to review and fix the issue before disclosing it publicly or sharing it with others
  • Do not interact with or access private accounts without the account owner's explicit consent
  • Make a good-faith effort to avoid privacy violations, service disruptions, or data destruction
  • Do not exploit the vulnerability for any reason, including to demonstrate further risk or access sensitive data
  • Comply with all applicable local, state, and federal laws and regulations
Bounty Program

How Rewards Work

RIMORIMO LLC recognizes and rewards security researchers who help protect our platform by responsibly reporting vulnerabilities. Bounties are awarded at our sole discretion, based on risk level, impact, and report quality. To potentially qualify for a bounty, you must:

  • Follow all of the fundamentals listed above
  • Report a valid security vulnerability that poses a genuine risk to user privacy or platform security
  • Submit your report directly to Contact@rimorimo.com — please don't contact employees directly
  • Disclose any accidental privacy violations or service disruptions that occurred during your research
  • Understand that response priority is based on risk severity and confirmed reports may take time to resolve
Rewards by Severity

What Each Severity Tier Pays

Rewards are based on the impact and severity of the reported vulnerability. Please include detailed, reproducible steps — issues that can't be reproduced aren't eligible for a bounty. The first valid report of a given issue receives the bounty; multiple bugs caused by a single underlying issue are treated as one report.

Critical Severity — $200

  • Remote code execution
  • Remote shell or command execution
  • Vertical authentication bypass
  • SQL injection leaking customer data
  • Full account takeover

High Severity — $100

  • Lateral authentication bypass
  • Disclosure of sensitive internal data
  • Stored XSS affecting other users
  • Local file inclusion
  • Insecure handling of authentication cookies

Medium Severity — $50

  • Logic or business process flaws
  • Insecure direct object references
  • CSRF on sensitive actions
  • Unvalidated redirects to external sites

Low Severity — Recognition Only

  • Open redirects
  • Reflected XSS
  • Low-sensitivity information leaks
  • Missing security headers
Non-Reportable Issues

What's Out of Scope

  • Denial of service (DoS/DDoS) attacks or testing
  • Spam or social engineering attacks
  • Physical security issues
  • Vulnerabilities in third-party services or plugins not directly controlled by RIMORIMO LLC
  • Reports generated solely by automated scanning tools without manual validation
  • Issues already known to our team or previously reported
How to Submit a Report

What to Include

To report a security vulnerability, send an email to Contact@rimorimo.com with the subject line: "Security Vulnerability Report — rimorimo.com". Your report should include:

  • A clear description of the vulnerability
  • Step-by-step instructions to reproduce the issue
  • The potential impact of the vulnerability
  • Any screenshots, videos, or proof-of-concept code, if applicable
We'll acknowledge your report within 3 business days and keep you informed of our progress throughout the resolution process.

Ready to Submit a Report?

Reach out any time — we respond to every inquiry within a few hours, 24/7.

Ready to Submit a Report?
Support Hours
24/7, Every Day
Address
121 Kemper Dr, Nicholasville, KY 40356
We acknowledge every valid report within 3 business days.