Incident Response Policy

Last updated: August 11, 2026

This policy describes how Ruligent detects, classifies, and communicates about operational and security incidents affecting the service or customer data.

1. Severity levels

Because Ruligent SDKs fail closed by default, a full outage of the guard endpoint blocks guarded agent actions rather than letting them through; severity classification accounts for this containment property.

2. Detection

Incidents are detected through health-check monitoring of the API, error reporting (Sentry), platform log review, and reports from customers or security researchers to www.ruligent.com/contact.

3. Notification commitments

4. Response process

  1. Triage and classify the report against the severity levels above.
  2. Contain — including, where warranted, use of the platform kill switch, key revocation, or taking the affected component offline.
  3. Remediate the root cause and verify the fix in production.
  4. Notify per the commitments above.
  5. Review — a blameless post-incident review within 10 business days for SEV-1 and SEV-2 incidents, covering root cause, timeline, and prevention. A summary is available to affected customers on request.

5. Reporting an incident or vulnerability

Report suspected incidents or security vulnerabilities to www.ruligent.com/contact. See the Security Overview for our responsible disclosure practice. We do not pursue legal action against good-faith research.

Contact

Incident response contact: www.ruligent.com/contact (founder on-call).