We welcome good-faith reports from the security community. This page explains the current reporting channel and authorization boundaries.
Last reviewed:
security@ryha.devIf you believe you have found a security vulnerability in a RYHA Technologies property, report it to security@ryha.dev. Include a clear description, the affected URL or component, reproduction steps, potential impact, and only the minimum proof-of-concept material needed to explain the issue. Do not include credentials, unrelated personal information, or customer data. RYHA does not promise a universal acknowledgement, remediation, or disclosure timetable; handling depends on severity, reproducibility, operational capacity, and legal review.
The public ryha.dev application and its RYHA-controlled endpoints may be considered only within the authorization limits below. Third-party provider systems, other customers’ accounts or data, social engineering, physical attacks, denial-of-service activity, credential attacks, destructive actions, and automated scanning that degrades service are out of scope. Report a suspected issue in a third-party service through that provider’s authorized channel unless the issue is caused by RYHA’s configuration or integration.
This page does not grant blanket testing authorization or a binding legal safe harbor. Use only accounts and data you control, stop if you encounter another person’s data or cause degradation, and obtain prior written authorization from RYHA before active security testing. A future safe-harbor commitment must be approved by qualified counsel and state its scope, conditions, excluded conduct, and applicable law. Until then, written authorization for the specific test controls.
RYHA intends to assess sufficiently detailed, good-faith reports, preserve an appropriate record, prioritize remediation according to verified risk, and coordinate disclosure where feasible. These are process goals rather than guaranteed response times, outcomes, rewards, or public credit. RYHA does not currently operate a paid bug-bounty program. Any acknowledgement or researcher credit is case-specific and requires permission and security review.
Reports are accepted in English at security@ryha.dev. A machine-readable contact record is available at https://ryha.dev/.well-known/security.txt in the RFC 9116 format. Do not use the reporting channel for general support, billing questions, or unauthorized testing requests.