Security

Last updated: 24 July 2026

Reporting a vulnerability

If you believe you have found a security issue, email hitliqiwei@gmail.com with details and steps to reproduce. Please give us a reasonable window to respond before public disclosure. We do not pursue good-faith researchers who follow responsible disclosure.

How raggate is built

Our honest threat model

The paid client ships as a compiled machine-code binary, which raises the bar against casual inspection and license tampering. We are candid that this is depth, not the wall. The durable enforcement is the server-side credit ledger, checked when a paid action runs. A tampered client still cannot spend credits it does not have.

Data & hosting

The portal runs on Render; authentication is via Clerk and payments via Stripe. See our Privacy Policy for what we collect and from whom.

Security is ongoing work. This page describes current practice and will evolve; the reporting address above is the fastest way to reach us.