1. Scope
1.1. This policy covers pilotlab.app, our public APIs, and our official client applications. Third-party services are out of scope.
2. How to report
2.1. Send a description of the issue, the steps to reproduce it, and any supporting material to security@pilotlab.app.
3. What we ask of you
- Give us a reasonable period to investigate and remediate before any public disclosure.
- Do not access, modify or delete data belonging to other users.
- Do not run denial-of-service tests or automated scanning that degrades the Services.
4. What you can expect from us
- Acknowledgement within one business day.
- A triage decision and severity assessment within five business days.
- Regular updates until the issue is resolved, and credit in our disclosure log if you would like it.
5. Out of scope findings
5.1. Reports limited to missing security headers, rate limiting on unauthenticated endpoints, or theoretical issues without a demonstrated impact are generally not eligible.
Report vulnerabilities to our security team. We aim to acknowledge within one business day.
security@pilotlab.app