01.Reporting Process
Email security@redpalm.ai with:
- A description of the vulnerability and its impact.
- Steps to reproduce (proof-of-concept where possible).
- The URL, endpoint, or component affected.
- Your contact details for follow-up.
Please do not open public issues, post details publicly, or contact staff through other channels for security reports.
02.Scope
- In scope: redpalm.ai, the DECISION ENGINE dashboard, and APIs we operate.
- Out of scope: third-party platforms we connect to, customer-owned websites, social engineering, physical attacks, denial-of-service, and spam/volume testing.
03.Rules of Engagement
- Only test against accounts you own or have permission to use.
- Do not access, modify, or exfiltrate data that is not yours; if you encounter someone else’s data, stop and report immediately.
- No degradation of service for other users.
- Give us reasonable time to remediate before any public disclosure.
04.Safe Harbor
We will not pursue legal action against, or refer to law enforcement, researchers who make a good-faith effort to follow this policy. We consider such research authorized under applicable anti-hacking and anti-circumvention laws to the extent we can authorize it.
05.Expected Response Times
- Acknowledgement: within 3 business days.
- Triage & initial assessment: within 10 business days.
- Remediation: prioritized by severity; we will keep you informed of progress on validated reports.
06.Responsible Disclosure
We coordinate disclosure timing with reporters. With your consent, we are happy to credit you once a fix has shipped. We do not currently operate a paid bounty program; if that changes, this page will say so.
07.PGP Key
Publish a PGP key and fingerprint for encrypted reports to security@redpalm.ai.
PGP fingerprint: [TODO — publish before launch]