Rakomi
ENPL

Responsible Disclosure Policy

Published: 2026-01-15 · Expires: 2027-01-15

We take security seriously and appreciate good-faith research. This page explains how to report vulnerabilities and what you can expect from us.

SDK Support & Lifecycle →Dated support windows of at least 5 years (60 months) per SDK major version (CRA Art. 13(8)), provenance & SBOM links, and our CRA-aligned support policy.

How to report a vulnerability

Send a report to security@rakomi.com. You may optionally encrypt your message with our PGP key.

We prefer reports in English or Polish.

Email security@rakomi.comDownload PGP key

Response SLAs

SeverityAcknowledgementFix target
Critical (RCE, auth bypass, data leak)24 hours7 days
High (privilege escalation, SSRF)48 hours30 days
Medium (XSS, CSRF, info disclosure)5 business days60 days
Low (best-practice deviations)10 business days90 days

Safe harbour

If you follow this policy in good faith, we will:

Please do not access, modify, or delete data that does not belong to you. Use only test accounts you own. We operate in the EU — Polish and EU law applies.

Out of scope

In scope

Authentication methods available on the platform include password sign-in, passwordless magic links, federated OAuth providers, time-based one-time passwords for multi-factor authentication, and phishing-resistant security credentials (passkeys). For passkeys we store only a public cryptographic identifier and minimal device metadata — no private key material and no raw device identifiers.

Hall of thanks

Researchers who have responsibly disclosed vulnerabilities to us will be listed here with their consent.

None yet — be the first.