Our commitment
Pentesys values good-faith security research. If you believe you have found a vulnerability in a Pentesys-controlled public system, please tell us promptly and give us a reasonable opportunity to investigate and remediate it before public disclosure.
How to report
Email sales@pentesys.com with “Security vulnerability” in the subject line. Include the affected asset, a clear description, reproduction steps, potential impact and any supporting evidence. Do not include unnecessary personal data or active malware. We will acknowledge valid reports and keep you informed where reasonably possible.
Research guidelines
- Act in good faith and only test Pentesys-controlled assets that are publicly accessible.
- Stop immediately if you encounter personal data, customer data, credentials or evidence of active compromise, and report what you found.
- Use the minimum testing needed to demonstrate the issue.
- Do not disrupt services, degrade availability, alter or destroy data, access another person’s account, use social engineering, conduct denial-of-service testing or install persistent access.
- Do not demand payment or make public disclosure before Pentesys has had a reasonable opportunity to respond.
Out of scope
Third-party services, customer systems, physical testing, social engineering, automated high-volume scanning, denial-of-service activity and findings that are purely informational without a credible security impact are out of scope unless Pentesys has given explicit written authorisation.
Good-faith research
Where research follows this policy, Pentesys will treat it as authorised for the limited purpose of reporting the vulnerability and will not intentionally pursue legal action. This statement does not authorise activity that is unlawful, affects third parties or falls outside this policy, and it cannot bind third parties.
