Legal
Security and Responsible Disclosure
How we protect the platform, and how to report a vulnerability.
Last updated 4 October 2026
How we protect your data
- Encrypted connections (TLS) everywhere, and documents encrypted at rest (AES-256-GCM).
- Two-factor authentication for every staff account; optional for clients.
- Every access to orders, reports, data rooms and identity documents is checked against your role and recorded in a tamper-evident audit log.
- Strict Content-Security-Policy, rate limits on sign-in and forms, malware scanning of uploads.
- Encrypted backups kept off the server, and regular restore tests.
Reporting a vulnerability
If you believe you have found a security problem, email contact@ragulikaip.com with the subject "Security" and enough detail for us to reproduce it. We will acknowledge your report within 3 business days and keep you informed.
Please
- Test only against your own account and data; do not access, change or delete other people's data.
- Do not run denial-of-service tests, spam or social-engineering attacks against staff or users.
- Give us reasonable time to fix the issue before telling anyone else.
We will not take legal action against research done in good faith within these rules. We don't run a paid bounty programme at present, but we are glad to credit you.