Legal
Security Disclosure Policy
How to report a vulnerability to Pinevon, what is in scope and how we will respond.
Version 0.2-draft · No effective date set yet · All legal documents
Draft — pending legal review. This document is a complete working draft prepared by the Pinevon team. It has not yet been reviewed by a lawyer and no effective date has been set. It describes how the service is actually built and operated today; bracket-free wording is deliberate, but jurisdiction-specific terms must be confirmed by qualified counsel before it is relied on.
1. Our commitment
We welcome reports from security researchers. If you find a vulnerability in a Pinevon service, tell us privately and give us reasonable time to fix it. We will not take legal action against good-faith research that follows this policy.
2. How to report
- Email security@pinevon.com with a clear description, affected URL or component, step-by-step reproduction, and the impact you believe it has.
- Include how to contact you and whether you want credit.
- Do not include real customer data in the report; a minimal proof is enough.
3. What to expect
| Step | Target |
|---|---|
| Acknowledgement | Within 3 business days |
| Triage and severity assessment | Within 7 days |
| Status updates | At least every 14 days until resolved |
| Fix for critical issues | As fast as possible; typically within 30 days |
| Credit | Public thanks with your consent once fixed |
These are targets, not guarantees. We do not currently run a paid bounty program.
4. In scope
- pinevon.com and its subdomains that we operate, including account.pinevon.com and app.pinevon.com
- Anchor web app and API at anchor.pinevon.com
- The installable Pinevon app
5. Out of scope
- Denial-of-service, volumetric or load testing.
- Social engineering, phishing or physical attacks against staff or customers.
- Spam or missing best-practice headers with no demonstrated impact.
- Vulnerabilities in third-party services we use — report those to the vendor.
- Findings that need a rooted device, outdated browser or already-compromised account.
6. Safe-harbor rules
- Only test accounts you own or have permission to use.
- Do not access, change, keep or share other people’s data; stop and report as soon as you can show impact.
- Do not degrade the service or run automated scanners at high volume.
- Do not disclose the issue publicly until we have fixed it or 90 days have passed, whichever is first, and we have agreed a date.
7. security.txt
Our contact details are also published at /.well-known/security.txt.