rouage exists because AI can write software faster than most teams can review it. Here is, concretely, what we do about that — for every build, not just the ones that ask.
Before anything reaches production, it goes through the same review discipline verrou applies to client systems: a threat model of what an attacker would actually want, a pass over the code and its dependencies, a check of authentication, authorization, and secrets handling, and a hardening round that closes what the review opens. The review isn’t a paid add-on or a checkbox — it’s the third phase of every engagement, and it has to finish before we ship.
We want to hear it, and you’ll reach a human — vulnerability reports are triaged ahead of everything else in the inbox. No form to fill out, no legalese to sign before you reach a person.
Email security@rouage.ai with the affected asset (URL, host, or endpoint), the steps to reproduce, and any proof-of-concept material. Sending something sensitive? Encrypt it with our security PGP key (rouage-security-pgp-key.asc). The machine-readable version of this policy lives at /.well-known/security.txt.
General correspondence uses a separate key — rouage-pgp-key.asc, for hello@rouage.ai. Two keypairs, deliberately: a disclosure key that several people may hold should not also open the sales inbox.
Give us reasonable time to investigate and fix before any public disclosure. Don’t access, modify, or exfiltrate data that isn’t yours, and don’t degrade the service for others. Research conducted in good faith along these lines will not be met with legal action — that’s a commitment, not a courtesy.
Every valid report gets a personal acknowledgement — ahead of everything else in the queue.
We reproduce the issue, assess its severity, and keep you updated as the investigation progresses.
Confirmed issues are fixed on a severity-driven timeline — and reporters who want recognition get it.
Whether we build it or review what you’ve built, the standard is the same.
Book a consult