Security · Disclosure

Responsible Disclosure Policy

Last updated: 2026-06-13 · Contact: security@pentes.io

If you've found a security vulnerability in pentes.io, we want to hear about it. This policy describes the scope, our commitments to you, what we ask of you, and how we coordinate disclosure. We honor good-faith security research and won't take legal action against you when you stay inside the boundaries below.

Where to send it

What's in scope

What's out of scope

Reports in these categories will be acknowledged but typically marked informational:

Out-of-scope reports that include a novel insight we hadn't considered are still useful — please send them.

Rules of engagement

To stay in safe harbor:

Our commitments to you (safe harbor)

Coordinated disclosure

Our default coordinated-disclosure window is 90 days from the date we acknowledge your report. Inside that window:

Rewards

We do not yet run a formal bug bounty program. We will send you a thank-you (and pentes.io swag where logistically possible) for valid reports, and we will credit you publicly. When we open a formal program with monetary rewards, prior disclosing researchers will be invited first.

What to include in a report

  1. A clear description of the vulnerability and where it lives (URL, endpoint, parameter).
  2. The steps a maintainer needs to reproduce it (curl one-liner, screenshot, proof-of-concept).
  3. Your assessment of impact (data accessible, user actions enabled, etc.).
  4. Any suggestions for remediation (optional but appreciated).
  5. Whether and how you want to be credited.

Hall of fame

Researchers who have responsibly disclosed issues to us will be listed here. (Currently empty — be the first.)