Security
Responsible disclosure
We welcome reports from security researchers and will work with you to fix genuine issues quickly.
Last updated16 September 2026
01 How to report
If you believe you have found a security vulnerability in plurentoo.com or another Plurentoo system, email connect@plurentoo.com with the subject line "Security vulnerability report". Please include:
- the affected URL or system;
- a description of the issue and its potential impact;
- clear steps to reproduce it, with screenshots or a proof of concept where helpful;
- how you would like to be credited, if at all.
Our security.txt file, which follows RFC 9116, lists the same contact details.
02 What we ask of you
- Act in good faith, and give us reasonable time to fix the issue before disclosing it publicly. We ask for up to 90 days from your report.
- Do not access, change or delete data that is not yours. Stop and report as soon as you encounter personal data.
- Do not run denial-of-service tests, spam, social engineering or physical attacks.
- Do not use automated scanners in a way that degrades the service for others.
- Comply with applicable law, including the Information Technology Act, 2000.
03 How we respond
- We acknowledge reports within 3 working days.
- We assess the report and keep you informed of progress.
- We fix confirmed issues as quickly as their severity requires.
- With your permission, we credit you once the issue is resolved.
04 Rewards
We do not run a paid bug bounty program, so we cannot offer payment for reports. We are glad to credit researchers who would like it.
05 Safe harbor
If you follow this policy, we will consider your research authorized, will not pursue legal action against you for it, and will work with you to understand and fix the issue. This does not cover systems owned by third parties, such as our hosting or email providers, whose own policies apply.
06 Out of scope
- Findings from automated scanners without a demonstrated impact.
- Missing security headers or best practices without a practical exploit.
- Clickjacking on pages with no sensitive actions.
- Reports about software versions without a working proof of concept.