Production boundary
RaiseFeed uses managed TLS, isolated production and staging databases, hashed one-time access tokens, secure HTTP-only cookies, least-privilege runtime identities, encrypted managed secrets, backups, and point-in-time recovery.
Data minimization
Application logs and traces are allowlisted. They must not contain email addresses, names, tokens, cookies, authorization headers, workspace notes, search text, job descriptions, raw provider payloads, or candidate data.
Report a concern
Email imran.hassan@rikhath.com with “Security” in the subject. Include the affected URL, reproducible steps, and impact without accessing other users' data. We target acknowledgment within one business day during the public launch period.
Do not include credentials, private customer content, or unnecessary personal data in the initial report. We may request a minimal proof through an appropriate channel.
Safe harbor
Good-faith research that avoids privacy harm, persistence, social engineering, denial of service, data destruction, and public disclosure before remediation will be handled constructively. This statement does not authorize access to third-party systems or data and is not a bug-bounty promise. Stop testing and notify us if you encounter personal data, credentials, or cross-tenant access.
Coordinated disclosure
Give us a reasonable opportunity to investigate and remediate before disclosure. We will confirm scope based on evidence, communicate material customer impact when required, and will not ask you to conceal an unresolved risk indefinitely.