Responsible disclosure
If you believe you have found a security vulnerability in a Propel system, we want to hear about it, and we will not take legal action against research that follows the rules below.
How to report
Email security@propelbsc.com with enough detail to reproduce the issue — the URL or endpoint, steps, and what you observed. We acknowledge within two business days and keep you informed until it is resolved.
The rules
- Test only against accounts you own or have explicit permission to use. Use a
pk_test_key if you are testing the API. - Do not access, modify or retain other people's data. If you encounter cardholder data, stop and tell us.
- No denial of service, no spam, no social engineering of our staff or clients.
- Give us a reasonable time to fix the issue before any public disclosure — we ask for 90 days.
In scope
propelbsc.com and its subdomains, propel-developer.com, propel-stock.com, api.propelbsc.com and the applications behind them. Third-party services we use are out of scope; report those to the vendor.
We do not currently run a paid bounty programme. We do credit reporters who want it.