Responsible Disclosure Policy
Effective Date: 2026-03-26
Overview
Pavri is committed to the security of our platform and the customers who rely on us. We welcome security researchers who identify vulnerabilities and report them to us in a responsible manner.
How to Report
Send vulnerability reports to security@pavri.ai.
Include:
- A description of the vulnerability and affected component
- Steps to reproduce or proof-of-concept code
- The potential impact and attack scenario
- Your contact information (for follow-up)
PGP encryption is available for sensitive reports — email security@pavri.ai to request our public key.
Our Commitments
When you report a vulnerability to us, we commit to:
- Acknowledge receipt within 2 business days
- Assess and triage within 7 business days and provide an expected resolution timeline
- Fix critical vulnerabilities within 48 hours of confirmation
- Fix high vulnerabilities within 7 days of confirmation
- Credit responsible reporters (with their permission) in our security acknowledgments
- Not take legal action against researchers who act in good faith and follow these guidelines
Researcher Guidelines
We ask that researchers:
- Do not access, modify, or delete any customer data — stop as soon as you can demonstrate the issue
- Do not perform denial-of-service attacks that could impact availability
- Do not exploit a vulnerability beyond what is necessary to demonstrate it
- Allow 90 days for us to remediate before publicly disclosing a vulnerability
- Not disclose the vulnerability to third parties during the 90-day disclosure window
- Act in good faith — only test against systems you own or have explicit permission to test
Scope
In Scope:
*.pavri.ai— all web properties- The Pavri Python SDK (PyPI:
pavri) - The Pavri platform API (
gateway.pavri.ai)
Out of Scope:
- Third-party services (WorkOS, Stripe, cloud providers) — report directly to the vendor
- Social engineering attacks against Pavri employees
- Denial-of-service testing
- Physical security
Not Eligible for Credit
The following are not eligible for security credits:
- Issues that require physical access to a device
- Self-XSS without a demonstrated impact to other users
- Missing security headers that do not constitute an exploitable vulnerability
- Theoretical vulnerabilities without demonstrated impact
- Issues already known to the Pavri team
Acknowledgments
We are grateful to the following researchers who have responsibly disclosed vulnerabilities to Pavri:
(No reports have been received yet.)
Contact
Email: security@pavri.ai Response Time: 2 business days
For general security questions: see our security overview.