Report vulnerabilities responsibly.
Email security@rlsok.com or use the repository's private GitHub Security Advisory channel. Do not include secrets in a public issue.
Supported versions
Supported public versions and release artifacts are listed on the Runtime releases page. Do not disclose an unresolved vulnerability in a public issue.
Security boundaries
Sessions and organization authorization are server-checked. Secrets remain server-side. Paddle webhooks require the exact raw request bytes, a current timestamp, and a valid HMAC signature; event IDs and occurrence times protect against retries and reordering. Paddle never grants robot dispatch authority.
Shadow and safety
Shadow has no dispatcher and reports Hardware dispatch: NO. RLSOK does not claim certified security, SOC 2, ISO 27001, penetration testing, functional safety, or E-stop replacement.