Skip to main content

Responsible disclosure

Security of risingcorporation.com

Procedure for confidentially reporting a vulnerability affecting only the risingcorporation.com website.

Last updated: 29 August 2026

Effective date: 29 August 2026

Section 1

Covered scope

This policy exclusively covers the website served at https://risingcorporation.com and its localised routes.

It does not cover any GitHub repository, software, package, product, API, third-party account, social network, other domain or subdomain unless expressly listed here.

Covered domain
risingcorporation.com

Section 2

Report a vulnerability

Send the report to security@risingcorporation.com. This address is reserved for vulnerabilities affecting the scope above.

Do not send any secret, personal data or intrusive evidence beyond what is strictly necessary to understand the issue.

Vulnerability reports
security@risingcorporation.com

Section 3

Useful information

  • A clear description of the observed behaviour and suspected vulnerability.
  • The precise URL or function concerned on risingcorporation.com.
  • Minimal, non-destructive reproduction steps.
  • The estimated impact and conditions required for it to occur.
  • A way to contact you if you wish to take part in coordination.

Section 4

Coordination and confidentiality

Rising Corporation limits access to a report to the people needed to assess and handle it.

To avoid increasing risk to users, please do not publish the vulnerability or exploitable details before explicit coordination.

Section 5

Limits of this policy

This page does not authorise testing, access to or alteration of any system. It provides a reporting channel only.

  • GitHub repositories and their infrastructure.
  • Software, packages, models, products and services other than the website.
  • Third-party accounts, social services, internal systems, other domains and subdomains.
  • Any destructive action, disruption, denial of service, social engineering, data access or persistence.

Section 6

Commitments and limitations

This policy promises no safe harbour, reward, acknowledgement or remediation deadline. No PGP key is announced until a verified public key is actually available.

Section 7

Reporter data

Supplied contact details, correspondence and technical material are processed to assess, coordinate and remediate the report, based on Rising Corporation’s legitimate interest in securing the website.

Information is accessible only to authorised personnel and retained during handling, then only as long as needed to document security or defend legal rights. Requests concerning this data may be sent to contact@risingcorporation.com.