Documentation

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Effective 23 September 2026 (revision 2). Last updated 23 September 2026 (revision 2).

If you find a security problem in rinkata, we want to hear about it. This page tells you how to report it, what we will do, and what we ask of you.

Who this covers

This is the vulnerability disclosure policy of Quirence, Inc., 700 El Camino Real, Suite 120 #1438, Menlo Park, CA 94025. It covers every Quirence product. This page lists the scope for rinkata.

How to report

Email security@quirence.ai. Do not open a public issue.

Include:

  • the affected URL or component
  • the steps to reproduce the issue
  • the impact, as you understand it
  • your own account email or workspace id

Never include another customer's data in a report.

For anything that is not a security issue, email support@quirence.ai.

What to expect

  • We acknowledge your report within 3 business days.
  • We triage it within 10 business days and tell you what we found.
  • We coordinate public disclosure with you at 90 days, or sooner once a fix ships. We can agree to extend that if a fix needs more time.

In scope

  • rinkata.dev, www.rinkata.dev, and api.rinkata.dev
  • the MCP endpoint
  • the OAuth authorization server, including client registration
  • the rinkata CLI and its local MCP server
  • the published rinkata plugin
  • the installer at rinkata.dev/install.sh (the one you run with curl | sh) and everything it fetches: the release archives and checksums in our release storage bucket, plus the release pipeline that publishes them

Out of scope

  • denial of service and load testing (our rate limits are deliberate)
  • social engineering and physical attacks
  • third-party services and MCP hosts, such as Stripe, Google, and Cloudflare. Bugs in those platforms are out of scope, but how we configure them is not: our own release bucket and its contents are in scope.
  • scanner-only reports with no demonstrated exploit, such as missing headers or DMARC and SPF settings
  • self-XSS
  • clickjacking on pages with no state-changing action
  • account enumeration with no further impact

Safe harbor

When you test rinkata:

  • test only against accounts and workspaces that you own
  • access no other customer's data beyond the minimum needed to show the issue, then stop and report it
  • do not degrade the service for other people
  • keep the details private until we have coordinated disclosure

If you follow this policy in good faith, we will not pursue legal action against you for that research.

We are updating the acceptable use section of the Terms of Service to refer to this policy.

Rewards

We do not currently offer monetary rewards.

Acknowledgments

We credit valid findings at medium severity or above that are reported under this policy. We list you only with your permission, and under the name you prefer.

No entries yet.