Anyone can report a vulnerability. We don't currently offer monetary rewards; we credit researchers who report valid issues responsibly, with their consent. Include clear reproduction steps so we can investigate your report.
In scope: getpropty.ai and all /t/* tenant app endpoints served from that domain.
Out of scope: third-party services (Stripe, Clerk, Vapi : report to them directly), social engineering, physical attacks, DoS / volumetric DDoS, automated scanner output without verified impact.
Safe harbor: Good-faith research is protected. Don't access production customer data : use the public demo with sample data at /demo. Don't disclose publicly before our fix is deployed (90-day coordinated disclosure).
Use the form below, or email hello@getpropty.ai.