RayShield

Security

Our security posture

We sell security, so we expect to be inspected. This page carries our own posture and the contact route for disclosure.

Reporting a vulnerability

Email security@rayshield.ai. The mailbox is monitored. A machine-readable contact is published at /.well-known/security.txt.

Site posture

  • No cookies, no third-party trackers, no marketing pixels, no session recording
  • Content-Security-Policy with an explicit allowlist, plus HSTS, X-Content-Type-Options, Referrer-Policy and Permissions-Policy
  • SPF, DKIM and DMARC configured before any outbound email is sent

Headers are set at the host, not in this static build — configure before launch