At RadTome and OrgSets, the security, data privacy, and isolation of multi-tenant communities, payment ledgers, and compliance documents are our highest priorities.
Please DO NOT report security vulnerabilities via public GitHub issues.
If you discover a security vulnerability in the OrgSets cloud platform, API, or authentication flow, please send a detailed disclosure report to:
- Security Team: security@radtome.com
- Urgent Issues: Use the official secure contact channel at https://radtome.com/contact
- Type of issue (e.g., cross-tenant authorization leak, privilege escalation, injection, cryptographic flaw).
- Step-by-step reproduction instructions or proof-of-concept.
- Affected endpoints, parameters, or UI views.
- An assessment of the potential impact.
- We acknowledge receipt of security reports within 24 hours.
- We will provide an estimated timeline for remediation.
- We will coordinate public disclosure after patches have been verified and rolled out across production environments.
Thank you for practicing responsible disclosure and keeping our communities secure!