Third Party Index

Snapshot 24577

Document
security.txt
URL
https://pensero.ai/.well-known/security.txt
Fetched
HTTP status
200
Content type
text/plain
Fetch mode
static
Size
1890 bytes
SHA-256 (raw)
70cbbbb19abed5f2543529bf0f4aff47cc6c38de575114b5bcf6a39056a37fa3
SHA-256 (normalized text)
31577aa491f5ca62811a9ff34fd9cb3330fbe93403a7a5996fcecbfbafb7dbe1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

# Pensero Security Policy
# https://securitytxt.org/ — RFC 9116
Contact: mailto:security@pensero.ai
Expires: 2027-03-18T00:00:00.000Z
Preferred-Languages: en
Canonical: https://pensero.ai/.well-known/security.txt
# Scope
# This policy covers the Pensero platform at https://pensero.ai
# and its associated APIs and services.
# Disclosure Policy
# We follow a coordinated disclosure process:
# 1. Report the vulnerability to security@pensero.ai
# 2. Include steps to reproduce, impact assessment, and any supporting evidence
# 3. We will acknowledge receipt within 2 business days
# 4. We will provide an initial assessment within 5 business days
# 5. We aim to resolve confirmed vulnerabilities within 30 days
# 6. We will notify you when the fix is deployed
# 7. Public disclosure is coordinated after the fix is live
# Bug Bounty
# We offer monetary rewards for qualifying vulnerability reports.
# Rewards are determined by severity and impact:
# Critical (RCE, auth bypass, data breach): up to $2,000
# High (privilege escalation, IDOR, stored XSS): up to $1,000
# Medium (CSRF, information disclosure): up to $500
# Low (open redirect, missing headers): up to $100
# To qualify, you must follow the disclosure policy above.
# Duplicate reports, known issues, and out-of-scope findings do not qualify.
# Final reward amounts are at our discretion.
# Out of Scope
# - Social engineering attacks against employees
# - Denial of service attacks
# - Automated scanning without prior authorization
# - Vulnerabilities in third-party services or dependencies (report to the vendor)
# Safe Harbor
# We will not pursue legal action against researchers who:
# - Act in good faith and follow this policy
# - Avoid accessing or modifying other users' data
# - Do not degrade or disrupt our services
# - Report findings promptly and do not disclose publicly before a fix is deployed