Security
Foundational, not bolted on
Our approach
Security is foundational to everything we build. As a company whose product
serves security teams, we hold our own engineering to the standard our customers
will hold us to.
Our practices include:
- A secure software development lifecycle, with code review required for all
changes.
- Encryption in transit for all services we operate, including this website,
which is served exclusively over HTTPS.
- Least-privilege access to our infrastructure, with multi-factor
authentication required across our accounts and tooling.
- Careful selection of cloud and software vendors, favoring providers with
strong, independently audited security programs.
Responsible disclosure
We appreciate the work of good-faith security researchers. If you believe you
have found a vulnerability in this website or in any Crimson Ray service, please
email security@crimsonray.ai.
Include enough detail for us to reproduce the issue.
We ask that you:
- Give us a reasonable opportunity to investigate and remediate before any
public disclosure.
- Avoid accessing, modifying, or destroying data that is not yours.
- Avoid actions that degrade service for others.
We will acknowledge legitimate reports promptly and keep you informed as we
address them. We will not pursue legal action against researchers who follow
these guidelines in good faith.