Trust
Security & Responsible Disclosure
PairRail Atlas handles seller commercial data and authentication for a multi-protocol agent-readiness control plane. We take security seriously and welcome good-faith research that helps keep sellers and buyers safe.
Security posture (high level)
- Platform — Atlas runs on Google Cloud: Firebase (Authentication and Hosting), Cloud Run for the API and protocol gateway, and Gemini / Vertex AI for commercial-truth extraction. Cloudflare provides DNS, CDN, and optional edge telemetry where configured.
- Authentication — Seller console sign-in via Firebase Authentication (Google / GitHub). Operator access is restricted to designated PairRail accounts.
- Transport — HTTPS for pairrail.com; CDN and edge protections via Cloudflare where configured.
- Separation of concerns — Public protocol endpoints serve published commercial projections; console and admin APIs require authentication and role checks.
- Operational telemetry — Seller auth/action and protocol usage events may be stored at the edge (Cloudflare D1/R2) for reliability and abuse detection; operator product actions are not forwarded into that seller telemetry path.
- Enterprise controls — Stronger isolation, signing, and key-management options (for example Cloud SQL with row-level security and Cloud KMS) are available for contracted Enterprise deployments; they are not implied for every Sandbox or Pro tenant.
- Billing — Card data is handled by the payment provider; PairRail receives entitlement and subscription metadata.
This page is not a warranty or audit certification. Controls evolve as the product matures.
Responsible disclosure
If you believe you have found a vulnerability in PairRail Atlas or pairrail.com, please email [email protected] with the subject line Security disclosure.
Include:
- A clear description of the issue and potential impact.
- Steps to reproduce (proof-of-concept limited to what is necessary).
- Affected URLs, endpoints, or console flows.
- Your contact information and preferred credit name (optional).
Please do
- Give us a reasonable time to investigate and remediate before public disclosure.
- Limit testing to accounts and data you own or are authorized to use.
- Avoid privacy violations, data exfiltration beyond proof, and service disruption.
Please do not
- Access, modify, or delete other customers’ catalogs, pricing, or evidence.
- Execute denial-of-service, social engineering of PairRail staff or customers, or physical attacks.
- Introduce malware or ransomware.
- Publicly disclose exploit details before we confirm a fix or mutually agree on timing.
Scope notes
In scope: pairrail.com application surfaces you reasonably believe we operate (console, APIs, protocol endpoints, edge telemetry/feedback paths). Out of scope unless we say otherwise: third-party services (Firebase, Google, GitHub, Cloudflare, payment providers) — report those to the respective vendor; misconfigured personal forks; and issues requiring unlikely user interaction with no security impact.
Our commitment
We will acknowledge receipt when practicable, prioritize based on severity, and notify you when a fix is deployed when you provide a valid contact. We will not pursue legal action against researchers who comply with this policy in good faith.
We do not currently operate a paid bug bounty. Recognition may be offered at our discretion.
Contact
[email protected] · Subject: Security disclosure