// trust

security is the operating model

rouage exists because AI can write software faster than most teams can review it. Here is, concretely, what we do about that — for every build, not just the ones that ask.

// engineering

how we build

  • Least privilege by default — every credential is scoped to the minimum access that works, and granted as late as possible.
  • Human-in-the-loop gates in front of anything irreversible: payments, deletions, external communications.
  • Audit trails — what the software (and the AI inside it) read and did is logged and reviewable after the fact.
  • Secrets are held in a secret manager, or in a root-owned, mode-restricted file the service reads at startup — never in code, never in a repository, never in a chat thread.
  • Dependencies are checked before they’re adopted — what they pull in, who maintains them, what their history looks like.
  • Client software gets tests in CI on every change, so a fix can’t silently break what shipped last week.
// review

every build is reviewed before it ships

Before anything reaches production, it goes through the same review discipline verrou applies to client systems: a threat model of what an attacker would actually want, a pass over the code and its dependencies, a check of authentication, authorization, and secrets handling, and a hardening round that closes what the review opens. The review isn’t a paid add-on or a checkbox — it’s the third phase of every engagement, and it has to finish before we ship.

// data

your data during an engagement

  • Access to your systems is requested narrowly, used for the step that needs it, and revoked at handover.
  • Development happens against sandboxes or synthetic data wherever the work allows it.
  • Client material stays segregated per engagement — findings, credentials, and evidence never mix across clients.
  • When engagement data is no longer needed, it’s securely deleted — written confirmation available on request.
  • What we hold about you and how long is covered plainly in the privacy policy.
// disclosure

found a vulnerability?

We want to hear it, and you’ll reach a human — vulnerability reports are triaged ahead of everything else in the inbox. No form to fill out, no legalese to sign before you reach a person.

how to report

Email security@rouage.ai with the affected asset (URL, host, or endpoint), the steps to reproduce, and any proof-of-concept material. Sending something sensitive? Encrypt it with our security PGP key (rouage-security-pgp-key.asc). The machine-readable version of this policy lives at /.well-known/security.txt.

General correspondence uses a separate key — rouage-pgp-key.asc, for hello@rouage.ai. Two keypairs, deliberately: a disclosure key that several people may hold should not also open the sales inbox.

what we ask of you

Give us reasonable time to investigate and fix before any public disclosure. Don’t access, modify, or exfiltrate data that isn’t yours, and don’t degrade the service for others. Research conducted in good faith along these lines will not be met with legal action — that’s a commitment, not a courtesy.

step 1 — acknowledge

a human reads it

Every valid report gets a personal acknowledgement — ahead of everything else in the queue.

step 2 — triage

we validate and assess

We reproduce the issue, assess its severity, and keep you updated as the investigation progresses.

step 3 — resolve

fixed, and credited

Confirmed issues are fixed on a severity-driven timeline — and reporters who want recognition get it.

// no bounty, no red tape — we don’t run a paid bounty program today, but every report gets a personal response from someone who can actually fix the issue.
// next step

want the same discipline on your build?

Whether we build it or review what you’ve built, the standard is the same.

Book a consult