Vulnerability Disclosure
The disclosure of security vulnerabilities helps us to ensure the security and privacy of our users. In order to maintain the security and privacy of both researchers and our users, we require that any potential submissions are made in line with the following guidelines.
Guidelines#
We require that all researchers:
- Make every effort to avoid privacy violations, degradation of our users’ experience, disruption to production systems, and destruction of data during security testing
- Test only against accounts and data they own or are authorised to use, and do not access, modify or delete data of other users
- Do not perform denial-of-service, spam, social-engineering, phishing or physical attacks
- Stop testing and report immediately if they encounter personal data or Organization Content of others
- Perform research only within the scope set out below
- Use the identified communication channels to disclose vulnerability information to us
- Keep information about any vulnerabilities they have discovered confidential between themselves and us until we have had 90 days to resolve the issue
Safe Harbor#
If you act in good faith and within these guidelines when reporting an issue to us, Patalyze will not file a criminal complaint (Strafantrag or Strafanzeige) against you, in particular under Sections 202a to 202d and 303a to 303b of the German Criminal Code (StGB), and will not assert civil claims against you for your research. Patalyze cannot bind public prosecutors, courts or third parties, including the providers listed as out of scope, and cannot authorise testing of their systems. If a third party takes action against you for research conducted in accordance with these guidelines, Patalyze will confirm on request that your research was authorised. Patalyze operates no bounty programme. We further commit to:
- Working with you to understand and resolve the issue quickly (including an initial confirmation of your report within 72 hours of submission)
- Processing the personal data you submit with a report as described in section 9 of the Privacy Policy
Within scope#
The following services are within the scope of this disclosure program:
- patalyze.com
- api.patalyze.com, including the MCP server at /mcp
- assets.patalyze.com
- crm.patalyze.com
- data.patalyze.com, including the MCP server at /mcp
- ws.patalyze.com
- releases.patalyze.com
- The Patalyze desktop application, including its update mechanism and locally stored data
Outside of scope#
Any services hosted by third-party providers are excluded from the scope. Application logic Patalyze deploys on these providers is in scope. The providers’ own infrastructure is not. These providers include, but are not limited to:
- Apple
- BetterStack
- Browserbase
- Cal.com
- Cloudflare
- Convex
- Lyceum
- Microsoft
- Notion
- PostHog
- Resend
- Stripe
- Vercel
How to report a security vulnerability#
If you believe you have found a security vulnerability in one of our products or platforms that is within the bounds of this program, please send an email to security@patalyze.com.