Legal
Security policy
Reporting a vulnerability
Email security@rapticore.com with a description of the issue and reproduction steps. Please do not perform intrusive testing against production tenants without prior written authorization.
What we commit to
- Acknowledgment within one business day.
- Regular status updates until the issue is triaged and fixed.
- Credit in our advisory if you request it.
- No legal action against good-faith researchers who follow this policy.
Scope
In-scope surfaces: this marketing site, the Ore Hammer tenant, the SentinelFlow tenant, and the ActiveFlux tenant. Out-of-scope: automated tools that produce high-volume noise, findings against third-party services we integrate with, and denial-of-service testing.