Skip to content
Rate Extra

Responsible disclosure

How to report a security vulnerability in rateextra.ae and what you can expect from us.

Version:
1.0
Effective date:
10/01/2026
Last updated:
09/22/2026

1. Scope

This policy covers the website rateextra.ae and its forms. Vulnerabilities in the TravelDistro API or the Hotel API should be reported to their operators (api@traveldistro.com, support@safaryarholidays.com).

2. How to report

Email legal@rateextra.ae with a description, steps to reproduce and any proof of concept. Our machine-readable contact is published at /.well-known/security.txt.

3. Rules of engagement

  • Do not access, modify or delete data that is not yours; use test data.
  • Do not run denial-of-service or automated scanning that degrades the service.
  • Do not disclose the issue publicly before we have had a reasonable opportunity to fix it.

4. Safe harbour

Research conducted in good faith and within these rules will not lead to legal action by Rate Extra.

5. What to expect

We acknowledge reports, keep you informed of progress and credit reporters who wish to be named once the issue is resolved. We do not operate a paid bounty programme.

This document is available in English, Arabic and Turkish. In case of conflict, the English version prevails to the extent permitted by applicable law.

Rate Extra Tourism L.L.C · License No. 1253634 · legal@rateextra.ae