Snapshot 24577
Normalized text
Scripts and page chrome removed; this is what change detection compares.
# Pensero Security Policy # https://securitytxt.org/ — RFC 9116 Contact: mailto:security@pensero.ai Expires: 2027-03-18T00:00:00.000Z Preferred-Languages: en Canonical: https://pensero.ai/.well-known/security.txt # Scope # This policy covers the Pensero platform at https://pensero.ai # and its associated APIs and services. # Disclosure Policy # We follow a coordinated disclosure process: # 1. Report the vulnerability to security@pensero.ai # 2. Include steps to reproduce, impact assessment, and any supporting evidence # 3. We will acknowledge receipt within 2 business days # 4. We will provide an initial assessment within 5 business days # 5. We aim to resolve confirmed vulnerabilities within 30 days # 6. We will notify you when the fix is deployed # 7. Public disclosure is coordinated after the fix is live # Bug Bounty # We offer monetary rewards for qualifying vulnerability reports. # Rewards are determined by severity and impact: # Critical (RCE, auth bypass, data breach): up to $2,000 # High (privilege escalation, IDOR, stored XSS): up to $1,000 # Medium (CSRF, information disclosure): up to $500 # Low (open redirect, missing headers): up to $100 # To qualify, you must follow the disclosure policy above. # Duplicate reports, known issues, and out-of-scope findings do not qualify. # Final reward amounts are at our discretion. # Out of Scope # - Social engineering attacks against employees # - Denial of service attacks # - Automated scanning without prior authorization # - Vulnerabilities in third-party services or dependencies (report to the vendor) # Safe Harbor # We will not pursue legal action against researchers who: # - Act in good faith and follow this policy # - Avoid accessing or modifying other users' data # - Do not degrade or disrupt our services # - Report findings promptly and do not disclose publicly before a fix is deployed