How to report a vulnerability
Write to security@pilae.com. The same address is published in our security.txt file at /.well-known/security.txt, following RFC 9116. We read reports in English, French and German.
A useful report includes:
- the affected URL, component or version;
- the steps to reproduce, in order;
- the impact you observed, such as data you could read or actions you could take;
- any proof of concept, screenshots or logs;
- how you would like to be credited, if at all.
Scope
In scope are pilae.com, the Pilae console, the Pilae Agent, the gate of the private network and the infrastructure of Pilae Cloud.
Out of scope are denial-of-service testing, social engineering of our staff or customers, physical attacks, spam, and findings from automated scanners without a demonstrated impact. A customer’s apps and data are not yours to test: if you come across them, stop and tell us.
A flaw in an open-source app itself, such as Nextcloud or n8n, belongs with its project. Report it through the project’s own process and tell us too. We protect our customers while the fix is prepared, and the Pilae Agent plans the patched release for every affected deployment once it exists. See security for how fixes reach customers.
Safe harbour
If you act in good faith and within this policy, we consider your research authorised. We do not file a criminal complaint or take legal action against you. In return, we ask you to:
- access no more data than you need to show the issue, and delete what you obtained once it is reported;
- avoid degrading our services or anyone else’s;
- give us reasonable time to fix the issue before you publish, ninety days by default;
- not use the issue for any other purpose.
We cannot waive the rights of third parties, such as customers or hosting providers. If you are unsure whether something is in scope, ask us at security@pilae.com first.
Our commitments
We acknowledge your report within two business days, send a first assessment within five business days and update you at least every ten business days until the issue is closed. Where a customer’s data is affected, we notify that customer as their data processing agreement requires. Once the fix is out, we publish an advisory and credit you if you wish.