Vulnerability Disclosure Policy

Last updated: August 28th, 2026

PocketApp is committed to the security of its systems and its users’ data. We value the work of independent security researchers and welcome reports of vulnerabilities discovered in good faith.

This policy explains how to report a vulnerability to us, what we ask of researchers, and what you can expect from us in return. It does not offer a monetary bounty, this is a responsible disclosure program.

Scope
In Scope
Out of Scope
  • Third-party services, vendors, or integrations we don’t directly control
  • Denial-of-service (DoS/DDoS) testing
  • Physical or social-engineering attacks on staff or offices
  • Non-production/staging environments not listed above

Not sure if something’s in scope? Ask us first: infosec@piggyvest.com.

Guidelines

When testing, please:

  • Avoid privacy violations, data destruction, and disruption to our services
  • Only use test accounts you own, or accounts you have explicit permission to use
  • Stop immediately and report to us if you encounter personal data, credentials, or other sensitive information, don't access, copy, or share it
  • Avoid automated high-volume scanning, spam, or brute-force testing
  • Give us a reasonable time to fix an issue before disclosing it publicly
  • Only use the contact channel below and don't disclose issues on social media or public forums first

Submitting a Vulnerability Report

Found something that could put Pocketapp systems or user data at risk? We want to hear about it. Send your findings to infosec@piggyvest.com, and help us move quickly by including the following in your report:

  • Issue Summary: A short, plain-language title capturing what you found (e.g., “Broken Access Control on Account Settings Endpoint”).
  • Impacted Asset: The exact URL, app screen, API endpoint, or IP address involved, so our team can locate it.
  • Impact: Explain the vulnerability itself and, just as importantly, what could go wrong if it were exploited (e.g data exposure, account takeover, funds at risk, etc.).
  • Reproduction Path: Walk us through it step by step. Assume we’re starting from zero and need to follow your exact path to see the issue ourselves.
  • Supporting Evidence (Proof Of Concept): Screenshots, a short screen recording, request/response logs, or a code snippet showing the exploit in action. Please redact any real user data before sending; if you're not sure whether something qualifies as sensitive, leave it out and describe it instead.
  • Contact Information: Your name or researcher handle, with the email address you'd like us to use for follow-up.

The more complete your report, the faster we can triage, validate, and get a fix moving.

What to Expect From Us
Acknowledgment of your reportWithin 3 business days
Initial triageWithin 10 business days
Status updatesAt least every 15 business days
ResolutionPrioritized by severity, timeline shared after triage

We’ll keep your report confidential and won't share your details without your consent, except where necessary to fix the issue or required by law.

Safe Harbor

If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will not pursue or support legal action against you for that research. This safe harbor applies only to testing conducted in line with the guidelines above.

Disclosure

We ask that you keep vulnerability details private until we’ve confirmed a fix is in place, or for 90 days after your report whichever comes first. We're happy to discuss a different timeline if a fix needs more time.

Recognition

This program doesn’t offer paid rewards, but we’re genuinely grateful for the time researchers put in, and we’re happy to acknowledge your contribution if you’d like credit.

Contact Information

Email: infosec@piggyvest.com

Thank you for helping keep Pocketapp and our users safe.