Security
Vulnerability Disclosure Policy
Found a security flaw in Penetrify? Email info@penetrify.cloud. We acknowledge every report within five business days, we do not threaten researchers acting in good faith, and we tell you when the issue is fixed. This programme is unpaid — what we offer is a straight answer on a timeline we actually hold, and public credit, not a payout.
Last updated 14 August 2026 · Machine-readable contact: /.well-known/security.txt
How to report
Email info@penetrify.cloud with the affected URL or endpoint, what an attacker can achieve, and the steps to reproduce it. A raw request or a short recording beats a scanner PDF. If you need to share something sensitive, say so and we will arrange an encrypted channel.
Please report each issue separately, and tell us if you intend to publish, so we can agree on timing rather than discover it later. We accept reports in English and Czech.
In scope
Out of scope
- —Volumetric denial-of-service, traffic floods and resource-exhaustion attacks.
- —Social engineering, phishing or physical attacks against our staff, offices or customers.
- —Scanner output with no demonstrated impact (missing headers, version disclosure, cookie flags on non-sensitive cookies).
- —Reports that require accessing another customer's data to prove — tell us the mechanism instead and we will reproduce it ourselves.
- —Findings in our customers' applications. Those belong to the customer; do not test a target because you saw it referenced in our product.
- —Vulnerabilities in third-party services we consume (report those to the vendor; tell us if our configuration is the problem).
- —Self-XSS, clickjacking on pages with no sensitive state, and issues only reachable with a browser or dependency already end-of-life.
Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorised. We will not pursue or support legal action against you, and if a third party brings a claim over research that complied with this policy, we will make it known that your activity was authorised.
Good faith means: stay within the scope above, use only your own test accounts, stop as soon as you have confirmed a vulnerability, do not access, modify, exfiltrate or destroy data that is not yours, do not degrade the service for others, and give us the disclosure window below before going public. If you are unsure whether something is in scope, ask first — we would rather answer a question than argue afterwards.
This is not permission to test our customers' systems, and it cannot waive the rights of third parties whose infrastructure we do not control.
What we commit to
Coordinated disclosure
We ask for 90 days from your report, or until a fix ships, whichever comes first. If we miss that window or stop responding, publish — a disclosure policy that lets the vendor stall forever is worthless, and we are not going to pretend otherwise. Let us know before you do, so we can have an honest answer ready for our customers. Because the programme is unpaid, nothing here asks you to stay quiet longer than that in exchange for anything.
If a flaw affects our customers' data, we will notify them on the timeline our contracts and applicable law require, whether or not the report is public by then.
Questions
Looking for testing of your own application rather than ours?