RyphexGuard
Marketplaceseparate Get started
RESPONSIBLE DISCLOSURE

Report a security issue without putting users at more risk.

If you believe you found a vulnerability in RyphexGuard, send enough detail for the issue to be reproduced safely. Do not exploit unrelated accounts, download unnecessary customer data, or publish secrets.

1

Describe the issue

Include the affected page/API, expected behavior, actual behavior and the minimum steps needed to reproduce it.

2

Limit the test

Use your own account/test server where possible. Stop after demonstrating the security impact; do not expand access beyond what is necessary.

3

Protect secrets

Do not send passwords, live bot tokens, API keys, payment credentials or complete OAuth tokens. Redact sensitive values from screenshots and logs.

4

Contact RyphexGuard

Email ryphexguard@gmail.com or use support with a clear “Security” subject. Include a safe contact method for follow-up.

What RyphexGuard does not promise

This page is a disclosure channel, not a bug-bounty promise. No reward amount, response SLA or safe-harbor legal guarantee is claimed unless RyphexGuard publishes one separately in writing.

Useful reports

  • Authentication or authorization bypass
  • Cross-account/server data access
  • Exposure of stored bot/OAuth/payment secrets
  • CSRF, injection or unsafe file handling
  • Marketplace balance/order authorization flaws
  • Admin privilege or team-permission bypass

Usually not a security vulnerability

  • Missing product features or design preferences
  • Rate limits working as intended
  • Issues caused only by unsupported browser extensions
  • Public information already designed to be public
  • Social engineering attempts against support staff
SECURITY CONTACT

ryphexguard@gmail.com

For ordinary account, billing or Marketplace support, use the normal support channel instead.

Email securityGeneral support