Security

Vulnerability Disclosure Policy

Issued by RegAlign Limited (Jersey company no. 165263). Linked from /.well-known/security.txt.

Our commitment

RiskAlign welcomes good-faith security research. If you find a vulnerability in our service, we want to hear from you — and we will not pursue legal action against researchers who follow this policy.

How to report

Email security@riskalign.app with subject line beginning [SECURITY]. Please include a clear description, steps to reproduce, the impact you believe it has, and (optionally) your contact details.

We acknowledge receipt within 2 business days, provide an initial assessment within 5 business days, and aim to remediate or have a mitigation plan in place within 30 days for high-severity issues.

In scope

  • riskalign.app, riskalignplatform.com, and any subdomain.
  • *.lovable.app deployments owned by RegAlign Limited that serve RiskAlign.
  • The published application, its public API endpoints (/api/public/* where present), and supporting infrastructure under our direct control.

Out of scope

  • Findings against third-party services we use (Cloudflare, our cloud provider, transactional email vendor, escrow agent).
  • Denial-of-service testing, social engineering, physical attacks.
  • Automated scanner output without a demonstrated exploit.
  • Missing security headers, certificate-grade issues, or version-disclosure findings that don’t lead to a concrete exploit.
  • Self-XSS, clickjacking on non-sensitive pages, and other findings without a realistic attack scenario.

Safe harbour

If you make a good-faith effort to comply with this policy, we will not pursue civil action, support criminal action, or notify law enforcement against you for accidental, good-faith violations. We consider your activity authorised under the UK Computer Misuse Act 1990 and the Data Protection Authority (Jersey) Law 2018, to the extent we are entitled to grant that authorisation.

This does NOT cover: accessing, modifying, exfiltrating, or destroying customer data; degrading or disrupting service for other users; or sharing the vulnerability with anyone else before we’ve had a reasonable opportunity to remediate.

Bounty

We don’t operate a paid bug bounty programme today (pre-funding). We do credit researchers publicly (with your permission) and will write to your employer, conference, or any other reference of your choice confirming the value of your work.

See also: Trust Centre · security.txt