Skip to main content

Responsible Disclosure Policy

Effective Date: 2026-03-26


Overview

Pavri is committed to the security of our platform and the customers who rely on us. We welcome security researchers who identify vulnerabilities and report them to us in a responsible manner.


How to Report

Send vulnerability reports to security@pavri.ai.

Include:

  • A description of the vulnerability and affected component
  • Steps to reproduce or proof-of-concept code
  • The potential impact and attack scenario
  • Your contact information (for follow-up)

PGP encryption is available for sensitive reports — email security@pavri.ai to request our public key.


Our Commitments

When you report a vulnerability to us, we commit to:

  • Acknowledge receipt within 2 business days
  • Assess and triage within 7 business days and provide an expected resolution timeline
  • Fix critical vulnerabilities within 48 hours of confirmation
  • Fix high vulnerabilities within 7 days of confirmation
  • Credit responsible reporters (with their permission) in our security acknowledgments
  • Not take legal action against researchers who act in good faith and follow these guidelines

Researcher Guidelines

We ask that researchers:

  1. Do not access, modify, or delete any customer data — stop as soon as you can demonstrate the issue
  2. Do not perform denial-of-service attacks that could impact availability
  3. Do not exploit a vulnerability beyond what is necessary to demonstrate it
  4. Allow 90 days for us to remediate before publicly disclosing a vulnerability
  5. Not disclose the vulnerability to third parties during the 90-day disclosure window
  6. Act in good faith — only test against systems you own or have explicit permission to test

Scope

In Scope:

  • *.pavri.ai — all web properties
  • The Pavri Python SDK (PyPI: pavri)
  • The Pavri platform API (gateway.pavri.ai)

Out of Scope:

  • Third-party services (WorkOS, Stripe, cloud providers) — report directly to the vendor
  • Social engineering attacks against Pavri employees
  • Denial-of-service testing
  • Physical security

Not Eligible for Credit

The following are not eligible for security credits:

  • Issues that require physical access to a device
  • Self-XSS without a demonstrated impact to other users
  • Missing security headers that do not constitute an exploitable vulnerability
  • Theoretical vulnerabilities without demonstrated impact
  • Issues already known to the Pavri team

Acknowledgments

We are grateful to the following researchers who have responsibly disclosed vulnerabilities to Pavri:

(No reports have been received yet.)


Contact

Email: security@pavri.ai Response Time: 2 business days

For general security questions: see our security overview.