ResponsibleDisclosurePolicy
How to report a suspected security vulnerability in Pentesys systems, and what happens next.
Last reviewed: 11 August 2026
Our commitment
Pentesys welcomes reports of suspected security vulnerabilities in systems we own or operate. If you report an issue in good faith and follow this policy, we will work with you on the issue and will not pursue legal action in relation to your research.
How to report a vulnerability
Email security@pentesys.com with enough detail for us to reproduce and assess the issue. A useful report normally includes:
- The affected URL, host or component.
- A clear description of the issue and its potential impact.
- Steps to reproduce, including any request or payload details.
- Screenshots, logs or proof-of-concept evidence where relevant.
- How you would like to be credited, if at all.
Scope
In scope: internet-facing systems owned and operated by Pentesys, including pentesys.com and our Mirage portal.
Out of scope: client systems and client data. Pentesys tests client environments only under written authorisation, and we cannot authorise testing of any third-party or client system. Third-party services we consume should be reported to that provider under their own disclosure policy.
Testing guidelines
When researching an issue, please:
- Only test against accounts and data that belong to you.
- Stop as soon as you have confirmed a vulnerability, and do not attempt to pivot further.
- Do not access, modify, exfiltrate or destroy data belonging to others; if you encounter personal data, stop and tell us.
- Avoid denial-of-service, volumetric or resource-exhaustion testing, spam, and social engineering of our staff, clients or suppliers.
- Do not use automated scanners at a rate that could degrade service availability.
- Do not publicly disclose the issue until we have had a reasonable opportunity to remediate it.
What to expect from us
When you submit a report under this policy, Pentesys will:
- Acknowledge receipt of your report.
- Triage the issue and assess its severity and impact.
- Keep you informed of progress towards remediation.
- Credit you publicly if you would like recognition and the issue is confirmed.
Rewards
Pentesys does not operate a paid bug bounty programme. We are grateful for good-faith reports and offer acknowledgement rather than financial reward.
Reporting an issue in a client environment
If you believe you have found a vulnerability in a system belonging to one of our clients, please report it to that organisation directly. Where you cannot identify a contact, you may email security@pentesys.com and, where we have a relationship with the organisation, we will pass the report on. Do not include exploit data for third-party systems in your message to us.
Report a vulnerability to security@pentesys.com.
