Vulnerability Disclosure Policy
Effective 23 September 2026. Last updated 23 September 2026.
If you find a security problem in rinkata, we want to hear about it. This page tells you how to report it, what we will do, and what we ask of you.
Who this covers
This is the vulnerability disclosure policy of Quirence, Inc., 700 El Camino Real, Suite 120 #1438, Menlo Park, CA 94025. It covers every Quirence product. This page lists the scope for rinkata.
How to report
Email security@quirence.ai. Do not open a public issue.
Include:
- the affected URL or component
- the steps to reproduce the issue
- the impact, as you understand it
- your own account email or workspace id
Never include another customer's data in a report.
For anything that is not a security issue, email support@quirence.ai.
What to expect
- We acknowledge your report within 3 business days.
- We triage it within 10 business days and tell you what we found.
- We coordinate public disclosure with you at 90 days, or sooner once a fix ships. We can agree to extend that if a fix needs more time.
In scope
rinkata.dev,www.rinkata.dev, andapi.rinkata.dev- the MCP endpoint
- the OAuth authorization server, including client registration
- the rinkata CLI and its local MCP server
- the published rinkata plugin
Out of scope
- denial of service and load testing (our rate limits are deliberate)
- social engineering and physical attacks
- third-party services and MCP hosts, such as Stripe, Google, and Cloudflare
- scanner-only reports with no demonstrated exploit, such as missing headers or DMARC and SPF settings
- self-XSS
- clickjacking on pages with no state-changing action
- account enumeration with no further impact
Safe harbor
When you test rinkata:
- test only against accounts and workspaces that you own
- access no other customer's data beyond the minimum needed to show the issue, then stop and report it
- do not degrade the service for other people
- keep the details private until we have coordinated disclosure
If you follow this policy in good faith, we will not pursue legal action against you for that research.
We are updating the acceptable use section of the Terms of Service to refer to this policy.
Rewards
We do not currently offer monetary rewards.
Acknowledgments
We credit valid findings at medium severity or above that are reported under this policy. We list you only with your permission, and under the name you prefer.
No entries yet.