RapidRoomZTM
Select Currency
Register Sign in
Information Security ISO/IEC 27001 & SOC2 Controls Updated September 2, 2026

Information Security & Vulnerability Disclosure Policy

Technical security controls, ISO/IEC 27001 standards, SOC2 framework, Stripe Level 1 PCI-DSS architecture, and Bug Bounty reporting guidelines.

Information Security Architecture Overview
  • End-to-End Encryption: TLS 1.3 protocol enforcing HSTS and 256-bit AES encryption across all public and API endpoints.
  • Stripe Level 1 PCI-DSS Architecture: Tokenized credit card entry operating in isolated iframe environments.
  • Continuous Security Scans: Daily automated dependency vulnerability audits, SAST scanning, and external penetration testing.
  • Responsible Disclosure Program: Security researchers can report vulnerabilities to security@rapidroomz.com for safe harbor acknowledgment.

1 Security Infrastructure & Controls

RapidRoomz employs bank-grade security protocols across all software layers. We enforce TLS 1.3 encryption in transit with HSTS headers and AES-256 encryption at rest for all stored application data. Our infrastructure operates under strict ISO/IEC 27001 operational standards.

2 Responsible Vulnerability Disclosure Policy

RapidRoomz welcomes reports from ethical security researchers. If you discover a security vulnerability in our web applications, APIs, or infrastructure, please report it responsibly:

🛡️ Security Desk Email: security@rapidroomz.com

✉️ Corporate Contact: ePorichoy LLC, 1209 Mountain Road Pl NE Ste R, Albuquerque, NM 87110, USA

We pledge not to initiate legal action against researchers who discover and report vulnerabilities in good faith under safe harbor guidelines without disrupting user services or accessing customer PII data.

Security FAQs

How can ethical security researchers report a vulnerability?

Send your detailed proof-of-concept report to security@rapidroomz.com. We review all reports within 24-48 hours and adhere to safe harbor guidelines.

Is user data encrypted at rest and in transit?

Yes. All data in transit is encrypted using TLS 1.3, and database storage utilizes AES-256 encryption at rest.