Security Disclosure Policy
RAGSec is a security company. We take vulnerability reports seriously, respond promptly, and commit to responsible handling of disclosures affecting our products or infrastructure.

How to report a vulnerability
Send vulnerability reports to security@ragsecurity.tech. Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any relevant HTTP requests, code snippets, or screenshots
- Any affected assets: ragsecurity.tech, the RAGSec application, or specific APIs
- Your contact information for follow-up
You may encrypt reports using our PGP key. Key details will be published here when available.
What to expect
- Acknowledgment: We will acknowledge receipt within 2 business days.
- Assessment: We will assess the report and communicate our initial finding within 5 business days.
- Resolution: We will work to resolve confirmed vulnerabilities and notify you when a fix is deployed.
- Coordination: We will coordinate disclosure timing with you before publishing any public advisory.
- Credit: We will credit researchers who report valid vulnerabilities unless they prefer anonymity.
Scope
In scope for this policy:
- The RAGSec application and APIs
- ragsecurity.tech and any RAGSec-operated subdomains
- RAGSec infrastructure directly under our control
Out of scope:
- Third-party services (Pinecone, Qdrant, Weaviate, WP Engine, Cloudflare) — report those directly to the affected vendor
- Social engineering attacks against RAGSec personnel
- Physical security
- Denial of service attacks
Safe harbor
RAGSec will not pursue legal action against researchers who discover and report vulnerabilities in good faith under this policy, provided that:
- The research does not access, modify, or delete data belonging to other users or customers
- The research uses only accounts and environments under the researcher’s own control
- The researcher reports the vulnerability to us before disclosing it publicly
- The researcher does not use the vulnerability for unauthorized access beyond what is necessary to demonstrate the issue
This is not a bug bounty program
RAGSec does not currently operate a paid bug bounty program. We do not offer monetary rewards for vulnerability reports at this time. We offer acknowledgment, coordination, and credit.