RODI considers the safety and security of Rotarians’ data to be one of its top priorities. This is why it strives to guarantee a very good level of security and reliability of its applications and systems. Despite its efforts to implement these security measures, vulnerabilities may still be present in its services and systems.
RODI is aware of the essential role of users and security researchers in the security of its services and systems and encourages them to report responsibly any vulnerabilities they may encounter while respecting the principles described in this policy.
Who ?
Everyone is encouraged to report identified vulnerabilities, regardless of the type of service or information system. Researchers, partners, CSIRT/CERT, members or any other source are welcome to report vulnerabilities.
How ?
The preferred method to contact RODI regarding these vulnerabilities is to send an email to
contact@rodi-platform.org
For confidential documents, RODI recommends using OpenPGP as the encryption system. Please use the public key available for download below.
https://www.rodi-platform.org/LinkClick.aspx?fileticket=4hgsUgTxP1A%3d&portalid=0
Personal data
Please note that :
Providing your contact details with your report is entirely voluntary and at your discretion;
RODI may use, for the purposes described below, all reports submitted, whether anonymous or containing contact details;
If you choose to provide your contact information, RODI will only use it to communicate with you to clarify the details of your report, if applicable. Under no circumstances will your contact details be used for purposes other than those for which you provided them. In particular, they will not be transmitted to any other entity;
Please review RODI's general privacy policy to learn how we respect the privacy of your personal data.
https://www.rodi-platform.org/district/declaration-de-confidentialite-rodi
When disclosing a vulnerability ethically
By disclosing an error or vulnerability to RODI, you confirm that you are acting responsibly by not taking advantage of the error or vulnerability, including that:
You have not exploited or used in any way, and will not exploit or use in any way (other than for the purpose of reporting to us), the discovered vulnerabilities and/or errors ;
You have not engaged, and will not engage, in testing/searching for vulnerabilities and/or errors with the intention of harming the Department, its constituents, agents, partners or suppliers;
You have not used, collected, deleted, altered or destroyed, and will not use, collect, delete, alter or destroy any data to which you have had access or may have access in connection with the vulnerability and /or the error discovered;
You have not carried out, and will not carry out, social engineering, spamming, phishing, denial of service or resource exhaustion attacks;
You have not violated and will not violate any applicable laws with respect to your report and your interaction with RODI services or information systems that led to your report;
You have not disclosed and agree not to disclose to any third party information relating to your report, reported vulnerabilities and/or errors, or the fact that a vulnerability and/or error has been reported to RODI. This non-disclosure commitment applies regardless of whether RODI has prior knowledge of the information or not.
By reporting to RODI through the method described above, or otherwise communicating a report to RODI, regarding vulnerabilities and errors in its services or systems, you agree that:
RODI may use your report for any purpose deemed relevant, including to correct vulnerabilities and errors that are reported and which RODI judges to exist and need to be corrected;
To the extent that you propose changes and/or improvements to a RODI service or system in your report, you authorize RODI, through itself or through the use of a third party, to use, implement, modify (including to adapt), disseminate and distribute these proposals and any resulting implementations. This authorization is given without compensation and for the entire world.
Our engagement :
To encourage responsible disclosure, RODI will endeavor not to take any action against any person submitting reports in accordance with this Policy and conducting testing/research on the Services or Systems without harm to RODI , to its administrators, its agents or third parties;
Not using or modifying any data to which it could access upon discovery;
Not engaging in social engineering, spamming or phishing attacks;
Not testing the physical security of RODI or third party assets and sites;
Not carrying out denial of service or resource exhaustion attacks;
Complying with applicable laws, including criminal laws.