Responsible disclosure: report a security vulnerability to Pilae

Found a vulnerability in a Pilae service? Write to security@pilae.com. We acknowledge every report, keep you informed while we fix it and do not take action against good-faith research.

Talk to our teamRequest the security pack

Report to
security@pilae.com
Acknowledgement
Within two business days
Languages
English, French, German
security.txt
/.well-known/security.txt

Our disclosure policy

We would rather hear about a flaw from you than from an attacker. The policy below says what we cover, what to send and what you can expect from us.

In scope

pilae.com, the Pilae console, the Pilae Agent, the private network gate and the infrastructure of Pilae Cloud.

Upstream apps

A flaw in an open-source app itself belongs with its project. Tell us too, and we help coordinate and protect our customers meanwhile.

What to include

The affected URL or component, the steps to reproduce, the impact you observed and any proof of concept.

Response times

Acknowledgement within two business days, a first assessment within five, and an update at least every ten.

Safe harbour

Research within this policy is authorised. We do not file a complaint or take legal action against it.

Credit

Once the fix is out, we credit you by name in the advisory if you wish.

How to report a vulnerability

Write to security@pilae.com. The same address is published in our security.txt file at /.well-known/security.txt, following RFC 9116. We read reports in English, French and German.

A useful report includes:

  • the affected URL, component or version;
  • the steps to reproduce, in order;
  • the impact you observed, such as data you could read or actions you could take;
  • any proof of concept, screenshots or logs;
  • how you would like to be credited, if at all.

Scope

In scope are pilae.com, the Pilae console, the Pilae Agent, the gate of the private network and the infrastructure of Pilae Cloud.

Out of scope are denial-of-service testing, social engineering of our staff or customers, physical attacks, spam, and findings from automated scanners without a demonstrated impact. A customer’s apps and data are not yours to test: if you come across them, stop and tell us.

A flaw in an open-source app itself, such as Nextcloud or n8n, belongs with its project. Report it through the project’s own process and tell us too. We protect our customers while the fix is prepared, and the Pilae Agent plans the patched release for every affected deployment once it exists. See security for how fixes reach customers.

Safe harbour

If you act in good faith and within this policy, we consider your research authorised. We do not file a criminal complaint or take legal action against you. In return, we ask you to:

  • access no more data than you need to show the issue, and delete what you obtained once it is reported;
  • avoid degrading our services or anyone else’s;
  • give us reasonable time to fix the issue before you publish, ninety days by default;
  • not use the issue for any other purpose.

We cannot waive the rights of third parties, such as customers or hosting providers. If you are unsure whether something is in scope, ask us at security@pilae.com first.

Our commitments

We acknowledge your report within two business days, send a first assessment within five business days and update you at least every ten business days until the issue is closed. Where a customer’s data is affected, we notify that customer as their data processing agreement requires. Once the fix is out, we publish an advisory and credit you if you wish.

What happens after you report

  1. Acknowledge

    An engineer confirms receipt within two business days and gives you a reference.

  2. Assess

    Within five business days we confirm whether we can reproduce it and how severe it is.

  3. Fix

    We fix it, check whether any customer is affected and notify them as their contracts require. You receive an update at least every ten business days.

  4. Disclose

    We agree a publication date with you. Our default is ninety days from your report, or earlier once the fix is deployed.

  5. Credit

    The advisory names you, if you wish, and describes the issue and the fix.

Our commitments to researchers

Acknowledgement
Within two business days of your report.
First assessment
Within five business days: reproduced or not, and the severity we assign.
Status updates
At least every ten business days until the issue is closed.
Coordinated disclosure
A publication date agreed with you, ninety days from the report by default.
Safe harbour
No complaint and no legal action against good-faith research within this policy.

Questions

How do I report a security vulnerability to Pilae?

Write to security@pilae.com in English, French or German. Include the affected URL or component, the steps to reproduce, the impact you observed and any proof of concept. The address is also published in our security.txt file at /.well-known/security.txt.

How quickly will Pilae respond?

We acknowledge every report within two business days, send a first assessment within five business days and update you at least every ten business days until the issue is closed.

Will Pilae take legal action against me?

No, not for good-faith research within this policy. We treat it as authorised and do not file a complaint or take legal action. We cannot waive the rights of third parties, such as a customer or a hosting provider, so keep your testing to the systems in scope.

Does Pilae pay bug bounties?

We do not run a paid bug bounty programme today. We credit researchers by name in our advisories if they wish.

What if the vulnerability is in an open-source app Pilae operates?

Report it to the upstream project through its own security process, and tell us too. We help coordinate the fix, protect our customers while it is prepared and roll it out once it is released.

Related

Found something? Tell us.

Write to security@pilae.com. An engineer reads every report and replies within two business days.