At RBC, we hold ourselves to the highest standards of integrity to build trust with every interaction. Our commitment is reflected in our dedication to protecting the security of our systems, our clientsâ privacy, and safeguarding the personal information entrusted to us.
RBC recognizes that fostering a close relationship with the community will help improve our security and we appreciate the contribution researchers and experts make to our security efforts. Thatâs why we encourage you to contact us directly to report potential vulnerabilities identified in any product or system belonging to RBC and its affiliates.
If you believe you have identified a potential security vulnerability, please submit it at [email protected] following the submission format outlined below. Thank you in advance for sharing your findings.
Please note, RBC does not operate a public bug bounty program and does not offer rewards or compensation in exchange for submitting potential issues.
Inquiries and support requests that are outside of the scope of this Responsible Disclosure Program may be directed to RBCâs Customer Service channels available at https://www.rbcroyalbank.com/customer-service/ .
RBC will not engage in legal action against individuals that submit vulnerability reports through the proper channel and in accordance with the following guidelines. As a responsible security researcher, you must:
Please note that RBC employees or contractors are not eligible to participate in the Responsible Disclosure Program.
RBC reserves all legal rights in the event of noncompliance with these guidelines.
Once a report is submitted, RBC commits to acknowledging receipt of reports within two business days of submission and will keep you reasonably informed of the status of any validated vulnerability that you report through this program. By submitting a report to RBC, you agree that:
If you believe you have discovered a vulnerability in our products or services, please send your report to [email protected] using the public key below to encrypt your email communication.
In your report, please provide a detailed summary of the vulnerability, including target(s), screenshots or video, attack scenario and steps to reproduce with timelines and time-zone information. Please also include a secure method to contact you.
Certain vulnerabilities are considered out of scope for our Responsible Disclosure Program. These include:
Physical or Social Engineering
Informational or Low-Risk Issues
Limited-Impact Findings
Non-Exploitable Behavior
Denial of Service (DoS)
By submitting a report to RBC, you are indicating that you have read, understand, and agree to these requirements.