Vulnerability Disclosure Policy

How to report a security vulnerability in Pilotlab, and what you can expect from us in return.

Last updated: March 2026 · Effective March 2026 · v0.1 (draft)

1.1. This policy covers pilotlab.app, our public APIs, and our official client applications. Third-party services are out of scope.

2.1. Send a description of the issue, the steps to reproduce it, and any supporting material to security@pilotlab.app.

  • Give us a reasonable period to investigate and remediate before any public disclosure.
  • Do not access, modify or delete data belonging to other users.
  • Do not run denial-of-service tests or automated scanning that degrades the Services.
  • Acknowledgement within one business day.
  • A triage decision and severity assessment within five business days.
  • Regular updates until the issue is resolved, and credit in our disclosure log if you would like it.

5.1. Reports limited to missing security headers, rate limiting on unauthenticated endpoints, or theoretical issues without a demonstrated impact are generally not eligible.

Report vulnerabilities to our security team. We aim to acknowledge within one business day.

security@pilotlab.app
Vulnerability Disclosure Policy | Pilotlab Legal