Security Disclosure Policy

RAGSec is a security company. We take vulnerability reports seriously, respond promptly, and commit to responsible handling of disclosures affecting our products or infrastructure.

Hero image: Security Disclosure Policy — Security Disclosure | RAGSec

How to report a vulnerability

Send vulnerability reports to security@ragsecurity.tech. Include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce, including any relevant HTTP requests, code snippets, or screenshots
  • Any affected assets: ragsecurity.tech, the RAGSec application, or specific APIs
  • Your contact information for follow-up

You may encrypt reports using our PGP key. Key details will be published here when available.

What to expect

  • Acknowledgment: We will acknowledge receipt within 2 business days.
  • Assessment: We will assess the report and communicate our initial finding within 5 business days.
  • Resolution: We will work to resolve confirmed vulnerabilities and notify you when a fix is deployed.
  • Coordination: We will coordinate disclosure timing with you before publishing any public advisory.
  • Credit: We will credit researchers who report valid vulnerabilities unless they prefer anonymity.

Scope

In scope for this policy:

  • The RAGSec application and APIs
  • ragsecurity.tech and any RAGSec-operated subdomains
  • RAGSec infrastructure directly under our control

Out of scope:

  • Third-party services (Pinecone, Qdrant, Weaviate, WP Engine, Cloudflare) — report those directly to the affected vendor
  • Social engineering attacks against RAGSec personnel
  • Physical security
  • Denial of service attacks

Safe harbor

RAGSec will not pursue legal action against researchers who discover and report vulnerabilities in good faith under this policy, provided that:

  • The research does not access, modify, or delete data belonging to other users or customers
  • The research uses only accounts and environments under the researcher’s own control
  • The researcher reports the vulnerability to us before disclosing it publicly
  • The researcher does not use the vulnerability for unauthorized access beyond what is necessary to demonstrate the issue

This is not a bug bounty program

RAGSec does not currently operate a paid bug bounty program. We do not offer monetary rewards for vulnerability reports at this time. We offer acknowledgment, coordination, and credit.