PocketApp is committed to the security of its systems and its users’ data. We value the work of independent security researchers and welcome reports of vulnerabilities discovered in good faith.
This policy explains how to report a vulnerability to us, what we ask of researchers, and what you can expect from us in return. It does not offer a monetary bounty, this is a responsible disclosure program.
Not sure if something’s in scope? Ask us first: infosec@piggyvest.com.
When testing, please:
Found something that could put Pocketapp systems or user data at risk? We want to hear about it. Send your findings to infosec@piggyvest.com, and help us move quickly by including the following in your report:
The more complete your report, the faster we can triage, validate, and get a fix moving.
| Acknowledgment of your report | Within 3 business days |
| Initial triage | Within 10 business days |
| Status updates | At least every 15 business days |
| Resolution | Prioritized by severity, timeline shared after triage |
We’ll keep your report confidential and won't share your details without your consent, except where necessary to fix the issue or required by law.
If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue or support legal action against you for that research. This safe harbor applies only to testing conducted in line with the guidelines above.
We ask that you keep vulnerability details private until we’ve confirmed a fix is in place, or for 90 days after your report whichever comes first. We're happy to discuss a different timeline if a fix needs more time.
This program doesn’t offer paid rewards, but we’re genuinely grateful for the time researchers put in, and we’re happy to acknowledge your contribution if you’d like credit.
Email: infosec@piggyvest.com
Thank you for helping keep Pocketapp and our users safe.