Responsible Disclosure Report a Vulnerability in Penva Security's Systems
Found a security vulnerability in Penva Security’s own systems? Thank you – this page tells you how to report it. We follow coordinated vulnerability disclosure norms aligned to ISO/IEC 29147, with safe harbour for good-faith research.
Responsible disclosure, safe harbour, and researcher trust
- ✓ 48-Hour Acknowledgement
- ✓ Safe Harbour
- ✓ Credit on Disclosure
Key trust signals
- Contact: security@penva...
- Alignment: ISO/IEC 29147
- Acknowledgement: Within 48 hours
- Investigation: 14-30 days typical
- Disclosure window: 90 days standard
- Safe harbour: Good-faith research
- Bug bounty: Recognition only
- security.txt: /.well-known/security.txt
How to report a vulnerability to Penva Security
Email [email protected] with vulnerability details. Penva Security will acknowledge receipt within 48 hours during Australian business hours, investigate within 14-30 days, and coordinate remediation. Standard public disclosure window is 90 days, extendable by mutual agreement.
How to report a vulnerability to Penva Security
/.well-known/security.txt, aligned to RFC 9116. Both reference the same security contact and PGP key. Trust Signals We Support
Recognised security practices, frameworks and methodologies used across Penva Security engagements.
What You Can Expect From Penva Security
Four timing commitments for valid disclosure reports. We hold ourselves accountable to these the same way we hold our clients accountable to remediation SLAs.
Acknowledgement
Status Update
Investigation
Disclosure Window
The Disclosure Process, Step by Step
Coordinated vulnerability disclosure has five phases. We’ve documented each one clearly so researchers know what to expect.
Send a Report via Encrypted Email
Email [email protected] with details of the vulnerability you’ve found. Use the PGP key referenced from our security.txt file for encrypted communications where sensitivity warrants.
Wait for Acknowledgement (within 48 hours)
Allow Investigation Time (typically 14-30 days)
Remediation & Verification
Coordinated Public Disclosure (optional, by mutual agreement)
What's In Scope and What Isn't
Clear scope helps everyone. Anything in-scope is welcomed under this policy; out-of-scope items have other appropriate channels.
Welcome Under This Policy
- penvasecurity.com.au and all subdomains we operate
- Client-facing portals and dashboards operated by Penva Security
- Email infrastructure and authentication systems
- Penva Security API endpoints and integration surfaces
- Any infrastructure that processes client engagement data
Other Channels Apply
- Third-party services Penva Security uses (report to those vendors directly)
- Vulnerabilities in client systems Penva Security has tested (those are confidential to the client)
- Social engineering of Penva Security staff (please don't)
- Physical attacks on Penva Security offices or staff
- Denial-of-service testing or volumetric attacks on Penva Security infrastructure
- Vulnerabilities already disclosed publicly or known to Penva Security
Protection for Good-Faith Researchers
Protection for Good-Faith Researchers
Good-faith research is protected
Penva Security commits to safe harbour for good-faith security research conducted within the scope of this policy. We will not initiate legal action against researchers who: act in good faith to identify and report vulnerabilities, stay within the in-scope systems above, avoid destructive testing or accessing data beyond what’s necessary to demonstrate the issue, and report findings to Penva Security before public disclosure.
What’s outside safe harbour: intentional data exfiltration, social engineering of staff, denial-of-service attacks, attempting to access other users’ data, public disclosure before coordinated disclosure window, and any activity that violates Australian or applicable law beyond authorised security research.
If you’re unsure whether something falls within scope or safe harbour, ask us first via the same security contact – we’d rather have a conversation upfront than navigate ambiguity later.
How to Reach Penva Security
One email address handles all disclosure reports. We commit to 48-hour acknowledgement during Australian business hours.
How to Reach Penva Security
Disclosure Policy — Common Questions
Direct answers to the questions security researchers ask. Updated May 2026.
Reporting a Vulnerability? Email [email protected]
48-hour acknowledgement during Australian business hours. PGP encryption available for sensitive reports via the key referenced in our security.txt file.