Vulnerability disclosure policy
If you have found a security problem in something we run, we want to hear about it, and we will not treat you as a threat for telling us.
How to report
Email security@penthropic.ai. Include enough detail for us to reproduce the issue: the affected URL or component, the steps, and what you observed. A short proof of concept helps more than a scanner report.
If the report contains sensitive detail and you would prefer to encrypt it, say so in a first message and we will arrange a channel.
What we commit to
- Acknowledgement
- Within 2 working days, from a human, not an autoresponder.
- Triage
- An initial assessment and a severity within 5 working days.
- Progress
- An update at least every 10 working days until it is closed.
- Resolution
- Critical and high issues targeted within 30 days. Medium and low within 90.
- Credit
- Public credit if you want it, and none if you do not. Your choice, asked before we publish.
- Legal position
- We will not pursue or support legal action against anyone who follows this policy in good faith.
Scope
In scope:
penthropic.aiand its subdomains.- The client portal and the administrative application.
- The Penthropic endpoint agent and the browser extension we publish.
- Our public API endpoints.
Out of scope, and we will close these without action:
- Findings from an automated scanner with no demonstrated impact.
- Missing security headers with no exploitable consequence.
- Rate limiting on unauthenticated endpoints, absent a real denial of service.
- Social engineering of our staff or our clients.
- Physical attacks on our offices or our people.
- Reports about software we do not operate, including our sub-processors. Report those to them.
- Self-inflicted issues that require a compromised device or a browser extension you installed.
What we ask of you
- Give us reasonable time to fix an issue before disclosing it publicly. 90 days is our default and we will usually be faster.
- Do not access, modify or delete data that is not yours. If you reach client data by accident, stop, and tell us what you saw.
- Do not run denial of service, spam, or physically destructive testing.
- Use only your own accounts and your own test data.
- Do not use a finding to pivot further into our systems than needed to prove it.
No paid bounty, stated plainly. We do not currently run a paid bug bounty programme, and we would rather say that than let you spend a weekend expecting one. You will get an acknowledgement, a fix, a written confirmation, and credit if you want it.
Our own disclosures
We publish gaps we find in our own configuration rather than fixing them quietly first. The demonstration page currently lists two open items on our own domain, with the commands to verify them.