Coordinated vulnerability disclosure.
We take the security of RAGSuite seriously. If you believe you’ve found a vulnerability in RAGSuite or ragsuite.de, we want to hear from you — and we’ll work with you to resolve it. Email security@ragsuite.de.
Tell us what you found.
Email security@ragsuite.de
Include the affected component and version, environment, steps to reproduce, and impact. Encrypt sensitive reports with our PGP key (see security.txt).
Report privately
Please give us a reasonable time to remediate before any public disclosure. Don’t open a public issue for a vulnerability.
We respond fast
We acknowledge within 3 business days and share an initial assessment within 10 — and we’ll credit you in the advisory if you wish.
What you can expect from us.
We acknowledge your report within 3 business days, assess it within 10, keep you updated through remediation, publish a security advisory once a fix is available, and credit you if you’d like. For actively exploited vulnerabilities or severe incidents we also meet our EU Cyber Resilience Act reporting obligations, which begin on 11 September 2026.
In scope, and out.
- The RAGSuite product (Community & Enterprise)
- ragsuite.de
- Third-party services we don’t operate
- Social engineering and physical attacks
- Volumetric denial-of-service
- Automated-scanner output with no demonstrated impact
Good-faith research is welcome.
We won’t pursue legal action for good-faith research that respects this policy: don’t violate privacy, don’t disrupt services, don’t access or exfiltrate data beyond a minimal proof-of-concept, and test only against your own deployment. If in doubt, ask us first at security@ragsuite.de.
This page summarises our coordinated vulnerability disclosure policy. The safe-harbour wording is being finalised with counsel and reconciled with our terms; it is provided in good faith. Security contact: security@ragsuite.de · /.well-known/security.txt. See also our Trust Center.
Report a vulnerability, or review our posture.
A published security contact and a coordinated-disclosure policy — built to the CRA. We respond.