Security

Last updated: 3 October 2026

RPMBase treats security as a core product responsibility. This page explains how we protect accounts and data, and how to report vulnerabilities responsibly.

1. Security practices

We use industry-standard controls appropriate for a product of our size and risk profile: encrypted transport (TLS) for production traffic, authentication with session and token controls, least-privilege access to production systems and secrets, monitoring with personal data scrubbing where feasible, and regular dependency and infrastructure updates.

Sensitive actions such as account deletion may be rate-limited or require additional verification.

2. Data protection

Personal data is processed as described in the Privacy Policy. Payment card data is handled by Apple or Google; RPMBase does not store full card numbers.

You can export garage data from Profile while signed in. Public deletion instructions are on the Account Deletion page.

3. Responsible disclosure

If you believe you found a security vulnerability in RPMBase, report it privately so we can investigate before public disclosure.

Email support@rpmbase.app with steps to reproduce, affected URLs or endpoints, and impact assessment. Do not access, modify, or destroy data that is not yours. Do not perform denial-of-service, social engineering, or physical attacks. Allow a reasonable time for remediation before public disclosure.

We aim to acknowledge valid reports within 3 business days and keep reporters informed of progress.

4. Out of scope

Reports limited to missing security headers without demonstrated impact, theoretical issues without a proof of concept, or vulnerabilities in third-party services outside our control are generally out of scope.

5. security.txt

Machine-readable contact details are published at https://rpmbase.app/.well-known/security.txt.

support@rpmbase.app