Responsible disclosure
How to report a security vulnerability in Rowsafe, and what to expect from us.
The Rowsafe agent runs with access to your data, so we take every report seriously.
Report vulnerabilities privately through GitHub security advisories. Please don't open a public issue.
Include what you found, how to reproduce it, and the impact you expect.
What to expect
- We acknowledge reports within 3 business days.
- We keep you updated until a fix is released.
- We credit you in the advisory, unless you prefer otherwise.
Scope
In scope: the agent, the CLI, the installer, the MCP server, update and release signing (everything in github.com/rowsafe/rowsafe), and the hosted service at rowsafe.sh.
Please don't test against other customers' data, and don't disrupt the service.
For anything else about security, write to [email protected].