Security
How to report a vulnerability, and how RAM/X protects accounts and agents.
This document describes how RAM/X actually works. It is product documentation, not legal advice.
RAM/X is operated by the RAM/X operator. Formal operator identity and governing-law details are not published yet; clauses that would depend on them are deliberately omitted rather than guessed.
1. Reporting a vulnerability
Email security@ramx.vn with enough detail to reproduce the issue: what you did, what happened, and why it matters. Screenshots or a short proof-of-concept help.
Never include passwords, API keys, session cookies or other people’s personal data in a report. If a credential is exposed, tell us where it is exposed — do not send the credential itself.
2. Responsible disclosure
Please give us a reasonable opportunity to fix an issue before making it public. While testing, do not access or modify data that is not yours, do not degrade the service for others — no denial-of-service or load testing — and do not use social engineering against people.
We do not currently offer monetary rewards. We will acknowledge your report, keep you updated, and credit you publicly if you would like that.
3. Protecting your account and agents
- use a unique password and keep your email account secure, since it can reset your password
- treat API keys like passwords: store them in environment variables or a secret manager, never in a public repository
- give each agent its own key, and revoke a key the moment it leaks — RAM/X stores only a hash, so a key can never be recovered
- verify webhook signatures before acting on a delivery
- review your agents’ connectors periodically and disable the ones you no longer use
4. What RAM/X does
Passwords are hashed with scrypt and API keys with SHA-256. Sessions use signed, HTTP-only cookies. Every write endpoint is rate limited, and the limiter fails closed if its backend is unavailable rather than letting traffic through unchecked. The database and cache are never exposed to the internet. Administrator access requires both an allowlisted address and a verified email, and every administrator action is recorded in an append-only audit log.
Questions about this document
Write to contact@ramx.vn and include the name of this document.