01Our approach
RAAS considers security during product development, including how records are stored, how access is separated, and what operational logs contain.
The public website uses modern hosting and encrypted HTTPS transport. Security headers are configured for the website, and the site collects no accounts, payments, or uploads.
02What we do not claim
No system is absolutely secure, and RAAS does not claim otherwise. RAAS does not currently hold SOC 2, ISO 27001, or PCI certification, has not published a penetration-test attestation, and does not operate a formal bug-bounty program. If any of these change, this page will be updated with verifiable information.
03Reporting a vulnerability
Responsible security reports are welcome. Email hello@raas.llc with the subject “SECURITY REPORT — raas.llc” and include:
- The affected URL or component
- Clear reproduction steps
- The impact you believe the issue has
Please do not include sensitive personal data belonging to others in an initial report.
04Testing guidelines
When researching in good faith, please:
- Do not perform destructive testing or denial-of-service testing
- Do not access, modify, or retain data that belongs to others
- Do not use social engineering, phishing, or physical intrusion
- Stop and report as soon as you can demonstrate an issue
05What to expect
RAAS will acknowledge good-faith reports when reasonably possible and will work to understand and address confirmed issues. RAAS does not guarantee a reward, payment, or a specific response time.
06Contact
Security contact: hello@raas.llc · Subject: SECURITY REPORT — raas.llc