RAAL Logo
Trust · Security

Report a security vulnerability

If you have found a security issue in Raal, we want to hear about it. This page explains what is in scope, how to reach us, what we will do, and the protection we offer researchers acting in good faith.

How to report

  • Email security@raal.io. Include the affected URL or component, steps to reproduce, and the impact you believe it has. Proof-of-concept code or screenshots help. You can report anonymously.
  • Please do not send reports through the contact form or support chat.
  • Machine-readable contact: https://raal.io/.well-known/security.txt

What we will do

01

Acknowledge

We confirm receipt within 2 business days.

02

Assess

We give you an initial assessment and severity within 5 business days, and keep you updated while we work on it.

03

Fix

We aim to resolve confirmed issues within 90 days. Critical issues that expose customer data are prioritized ahead of everything else.

04

Credit

We do not run a paid bounty program today. With your permission we credit you here once the issue is fixed.

Scope

In scope: raal.io and the subdomains Raal operates itself.

  • raal.io, the public website, including www.raal.io
  • help.raal.io, the help center
  • portal.raal.io, the customer portal
  • customerportal-api.raal.io, the customer portal API and the Raal MCP server
  • calculator-api.raal.io, the calculator API

Out of scope:

  • Third-party services we use (Featurebase, Attio, Cookiebot, Supabase, Cloudflare, Stripe). The Featurebase support widget and feedback portal are run by Featurebase; report issues in them to Featurebase.
  • Denial of service, load testing, spam, or anything that degrades service for other users.
  • Social engineering or phishing of Raal staff, customers or partners, and physical attacks.
  • Reports from automated scanners with no demonstrated impact, missing best-practice headers without an exploit, clickjacking on pages with no sensitive actions, and version disclosure on its own.

Rules for testing

  • Only test against accounts you own or have explicit permission to use.
  • Do not access, modify or delete data that is not yours. If you reach personal or customer data by accident, stop, do not copy it, and tell us.
  • Do not pivot to other systems, install persistence, or exfiltrate data beyond the minimum needed to show the issue.
  • Give us reasonable time to fix the issue before publishing. We will agree a disclosure date with you. If we go quiet for 90 days you may publish.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not start or support legal action against you for it, we will not report you to law enforcement for it, and we will work with you to understand and fix the issue.

If a third party takes legal action against you for activity carried out in line with this policy, we will confirm that your actions complied with it. This applies to the systems listed as in scope. It does not extend to third-party systems we do not control.

Policy version 1.0, effective 10 September 2026. Questions about this policy: security@raal.io.