Security & Responsible Reporting

Security is a shared responsibility. Protect your credentials, use multi-factor authentication where available, keep devices updated, and give users only the access they need.

Report a concern

Email support@rtp99.com with the subject Security report. Include the affected product or URL, the time and time zone, a clear description, and minimal reproduction steps. Ask for a suitable secure transfer method before sharing confidential evidence.

Keep reports safe

Do not send passwords, API keys, full payment-card details, donor records, or customer datasets by ordinary email. Redact screenshots. Stop testing if it exposes another person's data or could affect availability. Do not access, change, delete, or download data that is not yours, and do not test payment flows using unauthorized accounts.

Scope and expectations

This page provides a reporting channel; it is not permission to probe systems, a penetration-testing authorization, a bug bounty, or a legal safe-harbor commitment. Obtain written authorization for testing. We do not promise a specific response time unless your service agreement provides one. For an active payment-account compromise, also contact the processor using its official incident channel.

Assurance requests

Ask us for the documentation applicable to your service. This website makes no blanket claim that all RTP99 products or customers are PCI DSS, HIPAA, GDPR, SOC 2, or ISO certified or compliant. Controls, responsibilities, and contractual requirements must be assessed for the particular service and use case.