// trust

security is the operating model

rouage exists because AI can write software faster than most teams can review it. Here is, concretely, what we do about that — for every build, not just the ones that ask.

// engineering

how we build

// review

every build is reviewed before it ships

Before anything reaches production, it goes through the same review discipline verrou applies to client systems: a threat model of what an attacker would actually want, a pass over the code and its dependencies, a check of authentication, authorization, and secrets handling, and a hardening round that closes what the review opens. The review isn’t a paid add-on or a checkbox — it’s the third phase of every engagement, and it has to finish before we ship.

// data

your data during an engagement

// disclosure

found a vulnerability?

We want to hear it, and you’ll reach a human — vulnerability reports are triaged ahead of everything else in the inbox. No form to fill out, no legalese to sign before you reach a person.

how to report

Email security@rouage.ai with the affected asset (URL, host, or endpoint), the steps to reproduce, and any proof-of-concept material. Sending something sensitive? Encrypt it with our security PGP key (rouage-security-pgp-key.asc). The machine-readable version of this policy lives at /.well-known/security.txt.

General correspondence uses a separate key — rouage-pgp-key.asc, for hello@rouage.ai. Two keypairs, deliberately: a disclosure key that several people may hold should not also open the sales inbox.

what we ask of you

Give us reasonable time to investigate and fix before any public disclosure. Don’t access, modify, or exfiltrate data that isn’t yours, and don’t degrade the service for others. Research conducted in good faith along these lines will not be met with legal action — that’s a commitment, not a courtesy.

step 1 — acknowledge

a human reads it

Every valid report gets a personal acknowledgement — ahead of everything else in the queue.

step 2 — triage

we validate and assess

We reproduce the issue, assess its severity, and keep you updated as the investigation progresses.

step 3 — resolve

fixed, and credited

Confirmed issues are fixed on a severity-driven timeline — and reporters who want recognition get it.

// no bounty, no red tape — we don’t run a paid bounty program today, but every report gets a personal response from someone who can actually fix the issue.
// next step

want the same discipline on your build?

Whether we build it or review what you’ve built, the standard is the same.

Book a consult