Section 1
Covered scope
This policy exclusively covers the website served at https://risingcorporation.com and its localised routes.
It does not cover any GitHub repository, software, package, product, API, third-party account, social network, other domain or subdomain unless expressly listed here.
- Covered domain
risingcorporation.com
Section 2
Report a vulnerability
Send the report to security@risingcorporation.com. This address is reserved for vulnerabilities affecting the scope above.
Do not send any secret, personal data or intrusive evidence beyond what is strictly necessary to understand the issue.
- Vulnerability reports
- security@risingcorporation.com
Section 3
Useful information
- A clear description of the observed behaviour and suspected vulnerability.
- The precise URL or function concerned on risingcorporation.com.
- Minimal, non-destructive reproduction steps.
- The estimated impact and conditions required for it to occur.
- A way to contact you if you wish to take part in coordination.
Section 4
Coordination and confidentiality
Rising Corporation limits access to a report to the people needed to assess and handle it.
To avoid increasing risk to users, please do not publish the vulnerability or exploitable details before explicit coordination.
Section 5
Limits of this policy
This page does not authorise testing, access to or alteration of any system. It provides a reporting channel only.
- GitHub repositories and their infrastructure.
- Software, packages, models, products and services other than the website.
- Third-party accounts, social services, internal systems, other domains and subdomains.
- Any destructive action, disruption, denial of service, social engineering, data access or persistence.
Section 6
Commitments and limitations
This policy promises no safe harbour, reward, acknowledgement or remediation deadline. No PGP key is announced until a verified public key is actually available.
Section 7
Reporter data
Supplied contact details, correspondence and technical material are processed to assess, coordinate and remediate the report, based on Rising Corporation’s legitimate interest in securing the website.
Information is accessible only to authorised personnel and retained during handling, then only as long as needed to document security or defend legal rights. Requests concerning this data may be sent to contact@risingcorporation.com.