Responsible Disclosure
PLVN takes security vulnerabilities seriously. If you believe you have discovered a security issue in our platform, we want to hear from you. We operate a coordinated disclosure policy and commit to working with researchers in good faith.
How to Report
Email your findings to [email protected]. Please include:
- A clear description of the vulnerability and the potential impact.
- Steps to reproduce the issue, including any URLs, payloads, or screenshots that help us understand and reproduce it.
- Your name or handle (if you wish to be credited) and a contact email for follow-up.
Please encrypt sensitive reports using our PGP public key, available on request from the same address.
Our Commitments to You
- Acknowledgement. We will acknowledge receipt of your report within 2 business days.
- Communication. We will keep you informed of our progress and let you know when the vulnerability has been confirmed, when a fix is in development, and when it has been deployed.
- 90-day coordinated disclosure window. We ask that you give us 90 days from the date of acknowledgement to investigate and remediate the issue before public disclosure. If we need more time due to complexity, we will communicate this and work with you on an extended timeline. If we miss the deadline without communication, you are free to disclose.
- No legal action. Provided you conduct your research in good faith — meaning you do not access or exfiltrate real user data, do not degrade service availability, and do not use findings for personal gain — we will not pursue legal action against you in connection with your research.
- Credit. We will publicly credit researchers who responsibly disclose valid vulnerabilities, if they wish to be named.
Scope
In-scope targets include plvnapp.com and all its subdomains, the PLVN iOS and Android apps, and the PLVN API (api.plvnapp.com). Out-of-scope issues include denial-of-service attacks, social engineering of PLVN staff, physical attacks, and vulnerabilities in third-party services we use (please report those directly to the relevant vendor).
We do not currently offer a monetary bug bounty programme, but we sincerely appreciate the work of security researchers who help make PLVN safer for everyone.