Skip to main content

Legal

Security policy

Reporting a vulnerability

Email security@rapticore.com with a description of the issue and reproduction steps. Please do not perform intrusive testing against production tenants without prior written authorization.

What we commit to

  • Acknowledgment within one business day.
  • Regular status updates until the issue is triaged and fixed.
  • Credit in our advisory if you request it.
  • No legal action against good-faith researchers who follow this policy.

Scope

In-scope surfaces: this marketing site, the Ore Hammer tenant, the SentinelFlow tenant, and the ActiveFlux tenant. Out-of-scope: automated tools that produce high-volume noise, findings against third-party services we integrate with, and denial-of-service testing.