Security
Reporting a vulnerability in RelayFlow.
Last updated 1 September 2026
This is the vendor’s policy: how to report a vulnerability in the RelayFlow software itself, and what happens after you do. RelayFlow is a product of Astucia AI, a trade name of Rusanval Holdings, LLC.
If you are a customer or a user of someone else’s RelayFlow instance, the operator of that instance is a different party. They control their own deployment, data and disclosure practices; nothing here speaks for them.
How to report
Email security@mail.relayflow.dev.
Please include, as much as you have:
- what you found and where — a file and line, an endpoint, or a URL;
- how to reproduce it, ideally the smallest case that shows the problem;
- what an attacker gets out of it;
- the version you tested (
GET /api/healthreturns it, orrelayflow doctor); - whether you have disclosed it anywhere else, or intend to.
You do not need PGP. If you would rather encrypt, say so in a first message and we will arrange it.
Please do not open a public issue, post it publicly, or test against anyone else’s instance. If you need a target, run your own — the self-hosting guide that ships with the product gets you an appliance in a few minutes.
What we commit to
| Commitment | What it means |
|---|---|
| Acknowledgement | Within 3 business days, from a human, not an autoresponder. |
| Assessment | A severity and an intended fix window within 10 business days of acknowledgement. |
| Fix or mitigation | Critical 7 days · High 30 days · Medium 90 days · Low: next scheduled release. |
| Updates | At least every 10 business days while a report is open. |
| Credit | Named in the changelog if you want it, anonymous if you don’t. Your call, and we ask before publishing. |
These are targets we believe we can meet at our current size, not a contractual SLA. If we are going to miss one, we will tell you before we miss it rather than after.
The severity scale
Reports are rated on what an attacker gets, not on how clever the bug is. When a finding sits between two levels, we rate it higher.
- Critical — fix or mitigate within 7 days. Cross-tenant data access, remote code execution, or authentication bypass.
- High — fix or mitigate within 30 days. Privilege escalation within a tenant, credential disclosure, or a defect that sends mail as someone else.
- Medium — fix or mitigate within 90 days. Requires an unusual precondition, or the impact is bounded.
- Low — next scheduled release. Defence-in-depth, or a finding with no practical attack path.
When a report sits between two levels, we rate it higher. The scale above is the whole scale — it is published here so you can see what you are being measured against instead of taking our word for it. The internal runbook that sits behind it (how a report is tracked, fixed, announced and closed) is not public, but it adds no commitment beyond what is on this page.
Non-retaliation
If you make a good-faith effort to follow this policy, we will not pursue legal action against you and will not ask anyone else to. Good faith means: you did not access, modify or retain data that is not yours; you did not degrade anyone’s service; you did not use the finding for anything beyond demonstrating it; and you gave us a reasonable chance to fix it before going public.
This is a plain-language commitment, not a legal safe harbour — we are a small company and have not put a lawyer behind stronger wording. We would rather say that than imply a protection we have not actually bought.
Supported versions
| Version | Supported |
|---|---|
| Latest minor release | Security fixes. |
| Anything older | Not supported — upgrade first. |
We support the latest minor release only. There are no long-term-support branches and no backports. Releases are semver-tagged, and the appliance upgrade path is in the self-hosting guide that ships with the product.
What is in scope
The RelayFlow application, its API, the bundled relayflow CLI, the appliance bundle, the TypeScript SDK, and the MCP server.
Out of scope, and we will close these without a fix:
- findings against a specific operator’s instance rather than the software — report those to that operator;
- missing hardening that we already document as absent. The product’s own security documentation lists what it does not provide, with the board card that closes each. A report telling us there is no MFA is not a vulnerability report; it is that list, which we published ourselves;
- vulnerabilities in dependencies with no exploitable path through RelayFlow — though we do want to hear about them, and we will pick up the upgrade;
- social engineering, physical access, and denial of service by simply sending a lot of traffic;
- automated scanner output with no demonstrated impact.
What we do not offer
No paid bug bounty. A bounty needs a budget, a triage rota and a duplicate-handling policy, and we have none of those. Offering one we could not run would waste your time.
No certification, attestation or completed audit. RelayFlow holds none — not SOC 2, not ISO 27001, and no external penetration test has been commissioned yet. We say so here and in the product’s own documentation because a reviewer will ask, and the answer should be the same wherever you look.
Machine-readable contact
This site and every RelayFlow instance serve an RFC 9116 security.txt at /.well-known/security.txt, so a finder looking at any deployment is pointed back at us. On an appliance it is served by the application, not by the operator’s web server, so it is present on a default install with no operator configuration.
This website
A security problem in relayflow.dev itself — this site and its waitlist — goes to the same address. What the site stores and why is set out in the privacy notice.
Contact
security@mail.relayflow.dev — the only address for this. For anything that is not a security report, write to hello@mail.relayflow.dev instead.