Last Updated: 12 Jul 2025

1. Introduction

We take security seriously. If you believe you’ve found a security vulnerability in Raqib, we encourage you to report it responsibly so we can address it quickly.


2. How to Report

Send an email to support@raqib.ai with:

  1. Description of the issue
  2. Reproduction steps (if applicable)
  3. Impact and any suggested fixes
  4. Contact details for follow-up

3. In Scope

We welcome reports on:

  1. Authentication or session flaws
  2. Privilege escalation
  3. Insecure data exposure
  4. Misconfigured headers or CORS
  5. Vulnerable third-party integrations

4. Out of Scope

We do not consider the following as valid vulnerabilities:

  1. Self-XSS
  2. Lack of rate limiting on non-critical endpoints
  3. Spam or social engineering vectors
  4. Missing security headers with no exploitability

5. Rules of Engagement

  1. Do not access or modify data you don’t own
  2. Do not disrupt production services
  3. Do not use automated scanning tools
  4. Do not publicly disclose before we confirm and resolve the issue

6. Recognition

We currently do not offer a bug bounty, but we do acknowledge and thank ethical researchers.

...