Our commitment
Security is a core part of how we build Peutly. We know we won't catch everything, so we welcome reports from security researchers and anyone who spots a problem. If you report a genuine vulnerability in good faith, we'll work with you to understand it, fix it quickly, and keep you in the loop. This page explains how.
How to report
Email the details to security@peutly.com. A useful report usually includes:
- A clear description of the issue and its potential impact.
- Step-by-step instructions or a proof of concept to reproduce it.
- The affected URL, endpoint, or component, and any relevant account or request details.
- How you'd like to be credited, if the report is valid and you want acknowledgement.
If your report contains sensitive data, let us know and we'll arrange an encrypted channel. Please send reports in English or Dutch where you can.
What we promise in return
- We'll acknowledge your report within 3 business days.
- We'll give you an initial assessment, and a rough timeline for a fix, within 10 business days.
- We'll keep you updated on progress and let you know when the issue is resolved.
- We'll credit you in our acknowledgements below if you'd like, once the issue is fixed.
Safe harbour
If you make a good-faith effort to follow this policy, we will consider your research authorised, we will not pursue or support legal action against you for it, and we will work with you if a third party tries to. This authorisation covers only your own account or accounts you have explicit permission to test โ it does not extend to other customers' data. If in doubt about whether an action is allowed, ask us first at security@peutly.com.
Ground rules
- Give us a reasonable time to investigate and fix an issue before disclosing it publicly, and please coordinate any disclosure with us.
- Only interact with accounts you own or have permission to test. Don't access, modify or delete other people's data.
- Use the minimum access needed to demonstrate the issue โ don't pivot deeper or exfiltrate data once you've proven the point.
- Don't run attacks that degrade the Service for others, such as denial of service, spam, or high-volume automated scanning.
- Don't use social engineering, phishing, or physical attacks against our staff, users, or offices.
- Keep anything you learn about our systems or customers confidential.
In scope
Vulnerabilities in the systems we operate, for example:
- The Peutly application and dashboard.
- Our public website and hosted demo pages.
- Our documented APIs.
Typical issues we care about include authentication and authorisation flaws, injection, access-control and data-exposure bugs, server-side request forgery, remote code execution, and account-takeover paths.
Out of scope
These generally don't qualify on their own, unless you can chain them into a real, demonstrable impact:
- Reports from automated scanners with no proven exploitability.
- Missing security headers, cookie flags, or best-practice suggestions with no concrete impact.
- Clickjacking on pages with no sensitive actions, and self-XSS.
- Rate-limiting, brute-force, or denial-of-service concerns.
- Issues that require a rooted/jailbroken device, physical access, or a compromised network.
- Social engineering, phishing, or spam.
- Vulnerabilities in third-party services we don't control (please report those to the relevant vendor).
Rewards
Peutly doesn't run a paid bug-bounty programme at this time, but we deeply appreciate every valid report and are glad to offer public credit and, where appropriate, Peutly swag or account credit as a thank-you.
Acknowledgements
We're grateful to the researchers who have helped keep Peutly safe. With their permission, we recognise them here once reported issues are resolved. Want to be on this list? Send us a great report.
Reach the security team any time at security@peutly.com. For privacy questions, see our Privacy Policy.