Security policy

Found a real vulnerability in RAAD, the MCP server, the CLI, or this site? Email security@raad.app with enough detail to reproduce it. Please don’t open a public GitHub issue for anything that isn’t already public.

We don’t have a paid bug bounty program yet. We do commit to acknowledging a good-faith report within 5 business days, and crediting the reporter (unless they’d rather stay anonymous) once a fix ships.

For the full write-up of what RAAD stores, what a server can and can’t see, and what encryption in this product does and doesn’t protect against, see SECURITY.md in the repository.