Skip to content

Security: RadTome/OrgSets

Security

SECURITY.md

Security Policy

At RadTome and OrgSets, the security, data privacy, and isolation of multi-tenant communities, payment ledgers, and compliance documents are our highest priorities.

Reporting a Vulnerability

Please DO NOT report security vulnerabilities via public GitHub issues.

If you discover a security vulnerability in the OrgSets cloud platform, API, or authentication flow, please send a detailed disclosure report to:

What to Include:

  1. Type of issue (e.g., cross-tenant authorization leak, privilege escalation, injection, cryptographic flaw).
  2. Step-by-step reproduction instructions or proof-of-concept.
  3. Affected endpoints, parameters, or UI views.
  4. An assessment of the potential impact.

Our Commitment:

  • We acknowledge receipt of security reports within 24 hours.
  • We will provide an estimated timeline for remediation.
  • We will coordinate public disclosure after patches have been verified and rolled out across production environments.

Thank you for practicing responsible disclosure and keeping our communities secure!

There aren't any published security advisories