Security disclosure policy
Redgold runs tenant data on shared infrastructure, so we take security reports
seriously and want to make responsible disclosure easy. This page is the
canonical disclosure policy referenced by our /.well-known/security.txt.
Reporting a vulnerability
Email security@redgold.ai with a description of the issue, the affected endpoint or component, and enough detail to reproduce it. A proof-of-concept or minimal reproduction helps us triage quickly. English is preferred.
Please do not open a public issue, post to a forum, or disclose the problem publicly until we have had a chance to investigate and remediate.
Scope
In scope is anything under the Redgold platform: the public API surface
(api.redgold.ai, /v1/* and /api/*), the web application, the docs site,
and the agent and data-pipeline services behind them.
Out of scope: reports that require physical access to a user's device, social engineering of Redgold staff or users, denial-of-service or volumetric testing, spam or content-injection findings with no security impact, and issues in third-party services we depend on (report those to the respective vendor).
Safe harbor
We will not pursue or support legal action against researchers who act in good faith, follow this policy, avoid privacy violations and service degradation, and give us a reasonable opportunity to remediate before any disclosure. If in doubt about whether an action is authorized, ask first at security@redgold.ai.
What to expect
We aim to acknowledge a report within three business days and to provide an initial assessment shortly after. We will keep you updated as we work toward a fix and will let you know when the issue is resolved. We do not currently run a paid bug-bounty program; this policy covers coordinated disclosure only.