Responsible disclosure

If you believe you have found a security vulnerability in a Propel system, we want to hear about it, and we will not take legal action against research that follows the rules below.

How to report

Email security@propelbsc.com with enough detail to reproduce the issue — the URL or endpoint, steps, and what you observed. We acknowledge within two business days and keep you informed until it is resolved.

The rules

  • Test only against accounts you own or have explicit permission to use. Use a pk_test_ key if you are testing the API.
  • Do not access, modify or retain other people's data. If you encounter cardholder data, stop and tell us.
  • No denial of service, no spam, no social engineering of our staff or clients.
  • Give us a reasonable time to fix the issue before any public disclosure — we ask for 90 days.

In scope

propelbsc.com and its subdomains, propel-developer.com, propel-stock.com, api.propelbsc.com and the applications behind them. Third-party services we use are out of scope; report those to the vendor.

We do not currently run a paid bounty programme. We do credit reporters who want it.