The security of our products is important to us. If you have discovered a vulnerability in a RAFI product, please report it to us before disclosing it publicly.
We maintain two separate functional mailboxes, please select the appropriate one:
We ask that you do not publicly disclose suspected vulnerabilities without prior consent from RAFI.
If we cannot confirm a vulnerability, we will provide you with our assessment and rationale, and offer a direct discussion in case of differing evaluations.
If you act in good faith, adhere to this policy, and:
RAFI will not take legal action against you and will treat your report as a valuable contribution to product security.
Following the deployment of a remediation measure, we publish a Security Advisory detailing the issue, affected versions, severity rating, and recommended actions. In justified cases, publication may be deferred to allow users sufficient time to apply the update.