1. How to report
Email security@radras.com with the affected URL or asset, a clear description, reproducible steps, potential impact and any supporting evidence. Do not include unnecessary personal, client-confidential or regulated data.
For urgent reports, use the subject line “URGENT SECURITY REPORT”. This policy does not create a bug-bounty programme or promise payment.
2. Good-faith research guidelines
- Make a reasonable effort to avoid privacy violations, disruption, data destruction and degradation of service.
- Use only accounts and information you own or have explicit permission to test.
- Stop testing and report promptly if you encounter personal, confidential or client data.
- Do not use social engineering, phishing, physical intrusion, denial of service, malware or supply-chain compromise.
- Do not publicly disclose a vulnerability before RADRAS has had a reasonable opportunity to investigate and remediate it.
3. Scope
The public RADRAS website and domains expressly controlled by RADRAS are in scope for passive review and minimally invasive validation. Third-party services, customer environments, employee accounts and systems not expressly identified as RADRAS assets are out of scope.
Automated testing must be rate-limited and must not impair availability. If you are uncertain whether an activity is permitted, ask before proceeding.
4. What to expect
We aim to acknowledge a credible report within five business days, assess severity, maintain reasonable communication and coordinate remediation and disclosure where appropriate. Timelines vary with complexity, dependencies and risk.
5. Safe harbour
When research is conducted in good faith, follows this policy, avoids harm and is promptly reported, RADRAS will not initiate legal action solely for that research. This statement does not authorise activity against third parties, excuse violations of law or bind entities other than RADRAS.