Security
Report suspected vulnerabilities privately.
This page provides a reporting channel and boundaries; it does not authorize security testing.
Reporting a vulnerability
Email hello@raysor-technologies.com with “Security Report: Raysor Technologies website.” Include the affected URL, route, component, or commit; potential impact; minimal reproduction steps; whether personal information may be affected; and a safe contact method. Do not include secrets, full payment details, access tokens, or unnecessary personal information.
Research boundaries
Obtain written permission before testing production. Do not access or alter data that is not yours, disrupt availability, use social engineering, test Cloudflare, Stripe, Resend, or another third party, or disclose a suspected issue publicly before assessment. Stop immediately if you encounter personal information or unintended access.
No bug-bounty or payment commitment exists unless a separate written agreement says otherwise.
Operational security
The reviewed service uses Cloudflare Access for administrator routes, HTTPS and security headers, CSRF protection, Turnstile, request validation, prepared D1 statements, salted IP-derived rate limits, restricted audit records, and verified Stripe webhooks. These controls reduce risk but cannot guarantee security.
Supported versions
Security fixes are applied to the actively deployed version and current development line as operationally appropriate. No fixed support period or response time is promised.