Encryption is mandatory
RIPTON CLOUD is designed so transfers cannot be run in plaintext. Packet payloads are encrypted and authenticated as part of the protocol.
Effective date: May 7, 2026. This page describes RIPTON CLOUD's security posture, vulnerability reporting process, and testing expectations.
RIPTON CLOUD is designed so transfers cannot be run in plaintext. Packet payloads are encrypted and authenticated as part of the protocol.
Session keys are derived per session so compromise of one session does not expose previous or future sessions.
Authenticated packets, sequence handling, and replay windows are used to detect modification, injection, and replay attempts.
Structured transfer records, transfer identifiers, session identifiers, and error events are designed to support debugging and security review without exposing key material.
If you believe you have found a security issue in RIPTON CLOUD, email hello@riptoncloud.com with "Security report" in the subject line.
RIPTON CLOUD will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, report issues promptly, and follow this policy. This safe harbor does not apply to unlawful activity, extortion, data theft, destructive testing, or attacks against third parties.
Technical buyers can request a cryptographic design summary during evaluation. RIPTON CLOUD does not ask prospects to send sensitive production data through website forms. Evaluation data and deployment requirements should be discussed directly before testing sensitive workflows.