Security

Report vulnerabilities responsibly.

Email security@rlsok.com or use the repository's private GitHub Security Advisory channel. Do not include secrets in a public issue.

Supported versions

Supported public versions and release artifacts are listed on the Runtime releases page. Do not disclose an unresolved vulnerability in a public issue.

Security boundaries

Sessions and organization authorization are server-checked. Secrets remain server-side. Paddle webhooks require the exact raw request bytes, a current timestamp, and a valid HMAC signature; event IDs and occurrence times protect against retries and reordering. Paddle never grants robot dispatch authority.

Shadow and safety

Shadow has no dispatcher and reports Hardware dispatch: NO. RLSOK does not claim certified security, SOC 2, ISO 27001, penetration testing, functional safety, or E-stop replacement.