PairRail Atlas
Terms Privacy Security Acceptable use
Back to home

Trust

Security & Responsible Disclosure

Last updated: September 11, 2026 · Operators of pairrail.com (“PairRail”)

PairRail Atlas handles seller commercial data and authentication for a multi-protocol agent-readiness control plane. We take security seriously and welcome good-faith research that helps keep sellers and buyers safe.

Security posture (high level)

  • Platform — Atlas runs on Google Cloud: Firebase (Authentication and Hosting), Cloud Run for the API and protocol gateway, and Gemini / Vertex AI for commercial-truth extraction. Cloudflare provides DNS, CDN, and optional edge telemetry where configured.
  • Authentication — Seller console sign-in via Firebase Authentication (Google / GitHub). Operator access is restricted to designated PairRail accounts.
  • Transport — HTTPS for pairrail.com; CDN and edge protections via Cloudflare where configured.
  • Separation of concerns — Public protocol endpoints serve published commercial projections; console and admin APIs require authentication and role checks.
  • Operational telemetry — Seller auth/action and protocol usage events may be stored at the edge (Cloudflare D1/R2) for reliability and abuse detection; operator product actions are not forwarded into that seller telemetry path.
  • Enterprise controls — Stronger isolation, signing, and key-management options (for example Cloud SQL with row-level security and Cloud KMS) are available for contracted Enterprise deployments; they are not implied for every Sandbox or Pro tenant.
  • Billing — Card data is handled by the payment provider; PairRail receives entitlement and subscription metadata.

This page is not a warranty or audit certification. Controls evolve as the product matures.

Responsible disclosure

If you believe you have found a vulnerability in PairRail Atlas or pairrail.com, please email [email protected] with the subject line Security disclosure.

Include:

  • A clear description of the issue and potential impact.
  • Steps to reproduce (proof-of-concept limited to what is necessary).
  • Affected URLs, endpoints, or console flows.
  • Your contact information and preferred credit name (optional).

Please do

  • Give us a reasonable time to investigate and remediate before public disclosure.
  • Limit testing to accounts and data you own or are authorized to use.
  • Avoid privacy violations, data exfiltration beyond proof, and service disruption.

Please do not

  • Access, modify, or delete other customers’ catalogs, pricing, or evidence.
  • Execute denial-of-service, social engineering of PairRail staff or customers, or physical attacks.
  • Introduce malware or ransomware.
  • Publicly disclose exploit details before we confirm a fix or mutually agree on timing.

Scope notes

In scope: pairrail.com application surfaces you reasonably believe we operate (console, APIs, protocol endpoints, edge telemetry/feedback paths). Out of scope unless we say otherwise: third-party services (Firebase, Google, GitHub, Cloudflare, payment providers) — report those to the respective vendor; misconfigured personal forks; and issues requiring unlikely user interaction with no security impact.

Our commitment

We will acknowledge receipt when practicable, prioritize based on severity, and notify you when a fix is deployed when you provide a valid contact. We will not pursue legal action against researchers who comply with this policy in good faith.

We do not currently operate a paid bug bounty. Recognition may be offered at our discretion.

Contact

[email protected] · Subject: Security disclosure

PairRail Atlas

Seller-side commercial truth and multi-protocol agent-readiness infrastructure.

© 2026 PairRail. All commercial responses are indicative and governed by seller policy.
Legal Terms of Use Privacy Policy Code of Conduct Acceptable Use Security Cookie Notice
Support Support FAQ Home