Vulnerability Disclosure Program
Last updated: July 29, 2026
Pentone welcomes responsible disclosure of security vulnerabilities in our products and infrastructure. This program describes what is in scope, expected researcher conduct, how to report issues, and how we respond. We do not offer cash bounties. Valid in-scope findings may receive recognition and available merchandise.
Ready to submit a finding? Send it to:
Acknowledgement target: within 48 hours
1. Purpose
Pentone is a workspace for security teams to manage knowledge, run VAPT engagements, and generate reports. We treat security reports as a critical part of keeping the platform trustworthy for our customers. Researchers who test within the rules below help us identify and remediate issues before they cause harm.
Testing must remain non-destructive. Demonstrate impact with the minimum access and data needed to prove a finding. Do not delete, corrupt, or mass-modify production data, and do not access information that does not belong to you beyond what is required to document the issue.
2. Scope
2.1 In scope
- Authenticated product surfaces at app.pentone.io
- Public marketing site (pentone.io) and related documentation
- Authentication, session handling, MFA, and account recovery flows
- Workspace and tenant isolation boundaries
- API authorization flaws, IDOR, privilege escalation, and access-control bypasses
- Sensitive data exposure in application responses or stored artifacts
2.2 Out of scope
- Social engineering, phishing, or physical attacks against people or facilities
- Denial of service, DDoS, rate-limit exhaustion, or spam campaigns
- Vulnerabilities in third-party services we do not operate or control
- Findings that require compromising another user’s account without demonstrating a product defect
- Destructive testing that deletes, corrupts, or mass-modifies production data
- Automated scanner output without a clear, reproducible impact assessment
3. Rules of engagement
- Act in good faith. Limit testing to systems listed as in scope and stop if you encounter data that is clearly not yours.
- Do not access, modify, exfiltrate, or retain personal data, customer findings, or other confidential content beyond what is necessary to demonstrate the issue.
- Do not degrade service availability. Avoid aggressive automated scanning against production.
- Do not perform destructive actions against databases, storage, or production configurations. Report the vulnerability path; do not execute destructive payloads.
- Do not publicly disclose a vulnerability until we have remediated it or explicitly approved disclosure.
- Duplicate reports: recognition and rewards go to the first clear, actionable submission we can validate.
- We may decline rewards for known issues, previously reported findings, out-of-scope activity, or submissions that violate these rules.
Researchers who follow this policy in good faith will not face legal action from Pentone for security research conducted within these boundaries. This safe-harbor statement does not authorize activity that violates applicable law or third-party terms.
4. How to report
After confirming the issue is in scope and your testing followed the rules above, send your report to:
Acknowledgement target: within 48 hours
Each report should include:
- A clear summary of the vulnerability and its potential impact
- Affected URL, endpoint, or product surface
- Step-by-step reproduction instructions
- Proof-of-concept details (requests, screenshots, or minimal PoC code)
- Your preferred contact method and whether you want public credit
Encrypted email is not required. If you need to share sensitive attachments, note that in your message and we will arrange a secure channel when appropriate.
5. Response process
- Acknowledgement: We aim to acknowledge valid submissions within 48 hours.
- Triage: We assess severity, validate reproduction steps, and determine whether the issue is in scope.
- Remediation: We prioritize fixes based on impact and keep reporters informed of material status changes when practical.
- Disclosure: Please wait for remediation or our written approval before public discussion. Coordinated disclosure timelines can be agreed case by case.
6. Recognition and rewards
This is not a paid bug bounty program. For validated, in-scope findings, we may offer public credit (with your consent) and merchandise based on available inventory and report quality. Shipping is provided worldwide when feasible.
Examples of recognition items we may send:
- Sticker pack — Pentone vinyl sticker set and a written thank-you.
- Apparel + stickers — Limited VDP t-shirt or hoodie, sticker pack, and optional public credit.
- Insulated bottle — Branded steel bottle shipped when inventory allows.
- Desk accessories — USB-C hubs, cable kits, mechanical keycaps, or similar desk gear.
- Researcher kit — Combined apparel, bottle, stickers, and priority on limited drops.
Reward selection is at Pentone's discretion and is not guaranteed for every report.
7. Researcher acknowledgements
With your permission, we may list your name or handle on this page after a validated report is remediated. Anonymous reporting is always acceptable. Indicate your preference in your submission.
No public acknowledgements have been published yet. Validated reports with opted-in credit will appear here.
8. Career and collaboration
Strong research relationships matter to us. Depending on context, we may be able to:
- Referrals: Introduce capable researchers to security roles within our network when openings and fit align.
- Collaboration: Discuss longer-term collaboration or founding interest with people who want to help build Pentone (product, security, or go-to-market).
Mention interest in your disclosure email to [email protected], or contact [email protected].
9. Related policies
For platform architecture, encryption, and operational security practices, see our Security page. For personal data handling, see the Privacy Policy.
10. Contact
Security disclosures: [email protected]
General inquiries: [email protected]
Pentone Systems Inc.