# Security Policy — retrysight.com

This document covers the **RetrySight marketing website** at [retrysight.com](https://retrysight.com) — static pages, contact form, and related Cloudflare Pages assets.

For vulnerabilities in **RetrySight Lite** (open-source desktop app), see [retrysight-lite/SECURITY.md](https://github.com/arkaprava/retrysight-lite/blob/main/SECURITY.md).

For **RetrySight Cloud** or **Enterprise** (manager, dashboard, agents), include the affected product and deployment in your report.

## Reporting a vulnerability

**Please do not open public GitHub issues for security reports.**

Report issues through any of:

- Email: [contact@retrysight.com](mailto:contact@retrysight.com?subject=Security%20vulnerability%20report)
- Contact form: [retrysight.com/contact/](https://retrysight.com/contact/)
- [security.txt](https://retrysight.com/.well-known/security.txt) (RFC 9116)

Include:

1. Description of the issue and affected URL or component
2. Steps to reproduce
3. Impact assessment (confidentiality, integrity, availability)
4. Proof of concept if available
5. Your contact details for follow-up

## What we aim to do

- Acknowledge receipt within **3 business days**
- Provide a preliminary assessment within **10 business days** when possible
- Keep you informed of remediation progress
- Credit researchers in release notes when agreed (no obligation)

## Coordinated disclosure

We ask that you do not publicly disclose details until we have had a reasonable time to investigate and ship a fix. We follow coordinated disclosure practices and will work with you on timing.

## In scope (this website)

- retrysight.com and subdomains serving this marketing site
- Contact form (`/api/contact`) and related serverless handlers
- Misconfiguration or injection issues in site content delivery
- Cross-site scripting, open redirects, or CSRF affecting site visitors

## Out of scope

- Denial-of-service against public endpoints
- Social engineering or physical attacks
- Issues in third-party services (Cloudflare, Web3Forms) except where our integration is at fault
- Vulnerabilities in RetrySight product backends — report those with product context (Lite / Cloud / Enterprise)
- Missing security headers with no demonstrated exploit
- Automated scanner output without a verified exploit

## Security contact file

Machine-readable contacts: [/.well-known/security.txt](https://retrysight.com/.well-known/security.txt)

## Security review for Enterprise

For deployment architecture, data residency, and SSO documentation: [contact us](https://retrysight.com/contact/) or see [Security & Deployment](https://retrysight.com/security/).
