# Responsible disclosure

> How to report a security vulnerability in Rowsafe, and what to expect from us.

Source: https://rowsafe.sh/docs/security/disclosure

The Rowsafe agent runs with access to your data, so we take every report seriously.

**Report vulnerabilities privately** through [GitHub security advisories](https://github.com/rowsafe/rowsafe/security/advisories/new). Please don't open a public issue.

Include what you found, how to reproduce it, and the impact you expect.

## What to expect

- We acknowledge reports within **3 business days**.
- We keep you updated until a fix is released.
- We credit you in the advisory, unless you prefer otherwise.

## Scope

In scope: the agent, the CLI, the installer, the MCP server, update and release signing (everything in [github.com/rowsafe/rowsafe](https://github.com/rowsafe/rowsafe)), and the hosted service at rowsafe.sh.

Please don't test against other customers' data, and don't disrupt the service.

For anything else about security, write to [hello@rowsafe.sh](mailto:hello@rowsafe.sh).
