RPRED PALM

Security

Vulnerability Disclosure Policy

Found a security issue? Here is how to report it — and our commitment to you when you do.

Effective date: [TODO — set at launch] · Applies to DECISION ENGINE and redpalm.ai

Overview

Red Palm welcomes good-faith security research. This policy explains how to report vulnerabilities, what is in scope, the response you can expect, and the safe harbor we extend to researchers who follow it. The official security contact is security@redpalm.ai.

01.Reporting Process

Email security@redpalm.ai with:

  • A description of the vulnerability and its impact.
  • Steps to reproduce (proof-of-concept where possible).
  • The URL, endpoint, or component affected.
  • Your contact details for follow-up.

Please do not open public issues, post details publicly, or contact staff through other channels for security reports.

02.Scope

  • In scope: redpalm.ai, the DECISION ENGINE dashboard, and APIs we operate.
  • Out of scope: third-party platforms we connect to, customer-owned websites, social engineering, physical attacks, denial-of-service, and spam/volume testing.

03.Rules of Engagement

  • Only test against accounts you own or have permission to use.
  • Do not access, modify, or exfiltrate data that is not yours; if you encounter someone else’s data, stop and report immediately.
  • No degradation of service for other users.
  • Give us reasonable time to remediate before any public disclosure.

04.Safe Harbor

We will not pursue legal action against, or refer to law enforcement, researchers who make a good-faith effort to follow this policy. We consider such research authorized under applicable anti-hacking and anti-circumvention laws to the extent we can authorize it.

05.Expected Response Times

  • Acknowledgement: within 3 business days.
  • Triage & initial assessment: within 10 business days.
  • Remediation: prioritized by severity; we will keep you informed of progress on validated reports.

06.Responsible Disclosure

We coordinate disclosure timing with reporters. With your consent, we are happy to credit you once a fix has shipped. We do not currently operate a paid bounty program; if that changes, this page will say so.

07.PGP Key

TODO before launch

Publish a PGP key and fingerprint for encrypted reports to security@redpalm.ai.

PGP fingerprint: [TODO — publish before launch]

FAQ

Can I get in trouble for reporting a bug?

Not for good-faith research within this policy — that is exactly what the safe-harbor section protects.

Do you pay bounties?

Not at this time. We credit researchers (with consent) once fixes ship, and this page will be updated if a paid program launches.

Related policies