Security Policy
Our coordinated vulnerability disclosure policy. We welcome good-faith security research and will work with you to verify and resolve any issue.
1. Reporting a Vulnerability
If you believe you have found a security vulnerability affecting Raikiri, please email contact@raikiri.in. Include a clear description, the affected URL or endpoint, and steps to reproduce (a proof of concept is appreciated). Please do not disclose the issue publicly until we have had a chance to investigate and resolve it.
2. Scope
This policy covers raikiri.in and its subdomains. Our site is a statically rendered marketing site deployed on Cloudflare; findings such as misconfigurations, injection, authentication or authorization flaws, and exposure of sensitive data are in scope.
3. What to Expect
We aim to acknowledge your report within 5 business days, provide an assessment of its validity and severity, and keep you informed as we work toward a fix. With your consent, we are happy to credit you once the issue is resolved.
4. Safe Harbor
We will not pursue or support legal action against researchers who act in good faith and adhere to this policy. To stay within it: only test against accounts and data you own, avoid privacy violations and service degradation, do not run denial-of-service or automated scans that harm availability, and refrain from social engineering or physical attacks.
5. Out of Scope
Reports limited to missing best-practice headers without a demonstrated impact, rate-limiting concerns, theoretical issues without a working proof of concept, and findings from automated scanners without validation are generally considered low priority or out of scope.