# Security contact information for penetrify.cloud, per RFC 9116. # # Found a vulnerability in Penetrify itself? Email us. We read every report, we do not # threaten researchers who act in good faith, and we will tell you when the issue is fixed. # # This is an UNPAID programme: no monetary bounty, no swag. What you get is an # acknowledgement within 5 business days, a reproduction verdict within 20, updates at # least every 30 days until it is closed, and public credit if you want it. If you are # looking for a paid bounty, we would rather you know that before spending your time. # # These windows are deliberately unambitious: they are what a two-person team can hold in # a bad week, not what reads well on a policy page. # # Full scope, safe harbour and our response commitments are in the policy below. # Short version: do not test customer targets, use only your own accounts, and give us # 90 days (or until a fix ships) before publishing. # # Expires must stay less than a year out (RFC 9116 section 2.5.5) — renew it annually, # and note that both this file and the legacy copy at /security.txt carry the same content. Contact: mailto:info@penetrify.cloud Contact: https://www.penetrify.cloud/en/about/ Policy: https://www.penetrify.cloud/en/vulnerability-disclosure/ Expires: 2027-08-13T23:59:59.000Z Preferred-Languages: en, cs Canonical: https://www.penetrify.cloud/.well-known/security.txt Canonical: https://www.penetrify.cloud/security.txt