PairRail Atlas
Terms Privacy Security Acceptable use
Back to home

Trust

Security & Responsible Disclosure

Last updated: September 11, 2026 · Operators of pairrail.com (“PairRail”)

PairRail Atlas handles seller commercial data and authentication for a multi-protocol agent-readiness control plane. We take security seriously and welcome good-faith research that helps keep sellers and buyers safe.

Security posture (high level)

  • Platform — Atlas runs on Google Cloud: Firebase (Authentication and Hosting), Cloud Run for the API and protocol gateway, and Gemini / Vertex AI for commercial-truth extraction. Cloudflare provides DNS, CDN, and optional edge telemetry where configured.
  • Authentication — Seller console sign-in via Firebase Authentication (Google / GitHub). Operator access is restricted to designated PairRail accounts.
  • Transport — HTTPS for pairrail.com; CDN and edge protections via Cloudflare where configured.
  • Separation of concerns — Public protocol endpoints serve published commercial projections; console and admin APIs require authentication and role checks.
  • Operational telemetry — Seller auth/action and protocol usage events may be stored at the edge (Cloudflare D1/R2) for reliability and abuse detection; operator product actions are not forwarded into that seller telemetry path.
  • Enterprise controls — Stronger isolation, signing, and key-management options (for example Cloud SQL with row-level security and Cloud KMS) are available for contracted Enterprise deployments; they are not implied for every Sandbox or Pro tenant.
  • Billing — Card data is handled by the payment provider; PairRail receives entitlement and subscription metadata.

This page is not a warranty or audit certification. Controls evolve as the product matures.

Responsible disclosure

If you believe you have found a vulnerability in PairRail Atlas or pairrail.com, please email [email protected] with the subject line Security disclosure.

Include:

  • A clear description of the issue and potential impact.
  • Steps to reproduce (proof-of-concept limited to what is necessary).
  • Affected URLs, endpoints, or console flows.
  • Your contact information and preferred credit name (optional).

Please do

  • Give us a reasonable time to investigate and remediate before public disclosure.
  • Limit testing to accounts and data you own or are authorized to use.
  • Avoid privacy violations, data exfiltration beyond proof, and service disruption.

Please do not

  • Access, modify, or delete other customers’ catalogs, pricing, or evidence.
  • Execute denial-of-service, social engineering of PairRail staff or customers, or physical attacks.
  • Introduce malware or ransomware.
  • Publicly disclose exploit details before we confirm a fix or mutually agree on timing.

Scope notes

In scope: pairrail.com application surfaces you reasonably believe we operate (console, APIs, protocol endpoints, edge telemetry/feedback paths). Out of scope unless we say otherwise: third-party services (Firebase, Google, GitHub, Cloudflare, payment providers) — report those to the respective vendor; misconfigured personal forks; and issues requiring unlikely user interaction with no security impact.

Our commitment

We will acknowledge receipt when practicable, prioritize based on severity, and notify you when a fix is deployed when you provide a valid contact. We will not pursue legal action against researchers who comply with this policy in good faith.

We do not currently operate a paid bug bounty. Recognition may be offered at our discretion.

Contact

[email protected] · Subject: Security disclosure

PairRail Atlas

Seller-side commercial truth and multi-protocol agent-readiness infrastructure.

© 2026 PairRail. All commercial responses are indicative and governed by seller policy.
Legal Terms of Use Privacy Policy Code of Conduct Acceptable Use Security Cookie Notice
Support Support FAQ About Home