⬢ Vulnerability Disclosure · Updated May 2026

Responsible Disclosure Report a Vulnerability in Penva Security's Systems

Found a security vulnerability in Penva Security’s own systems? Thank you – this page tells you how to report it. We follow coordinated vulnerability disclosure norms aligned to ISO/IEC 29147, with safe harbour for good-faith research.

Responsible disclosure, safe harbour, and researcher trust

Designed for security researchers who need a clear, safe and documented path to report vulnerabilities in Penva Security systems.
At-a-glance

Key trust signals

A compact summary of the most important details visitors need before taking action.
Quick Answer

How to report a vulnerability to Penva Security

Email [email protected] with vulnerability details. Penva Security will acknowledge receipt within 48 hours during Australian business hours, investigate within 14-30 days, and coordinate remediation. Standard public disclosure window is 90 days, extendable by mutual agreement.

Quick answer

How to report a vulnerability to Penva Security

Email [email protected] with vulnerability details. Penva Security will acknowledge receipt within 48 hours during Australian business hours, investigate within 14-30 days, and coordinate remediation. Standard public disclosure window is 90 days, extendable by mutual agreement.
Penva Security commits to safe harbour for good-faith security research conducted in scope and consistent with this policy – we do not pursue legal action against researchers acting reasonably and reporting in good faith. We acknowledge reporters with credit (with consent) but do not currently offer monetary rewards.
The machine-readable counterpart to this policy lives at /.well-known/security.txt, aligned to RFC 9116. Both reference the same security contact and PGP key.
Certified & aligned with

Trust Signals We Support

Recognised security practices, frameworks and methodologies used across Penva Security engagements.

CR CREST
CR
OS OSCP
OS
OW OWASP
OW
Our SLAs

What You Can Expect From Penva Security

Four timing commitments for valid disclosure reports. We hold ourselves accountable to these the same way we hold our clients accountable to remediation SLAs.

48h

Acknowledgement

Receipt confirmation
14d

Status Update

Investigation cadence
14-30d

Investigation

Typical timeline
90d

Disclosure Window

Coordinated disclosure
Five-Step Process

The Disclosure Process, Step by Step

Coordinated vulnerability disclosure has five phases. We’ve documented each one clearly so researchers know what to expect.

01

Send a Report via Encrypted Email

Email [email protected] with details of the vulnerability you’ve found. Use the PGP key referenced from our security.txt file for encrypted communications where sensitivity warrants.

02

Wait for Acknowledgement (within 48 hours)

Penva Security commits to acknowledging valid disclosure reports within 48 hours of receipt during Australian business hours. The acknowledgement includes a tracking reference and an initial severity assessment.
03

Allow Investigation Time (typically 14-30 days)

Penva Security will investigate, reproduce, and validate the report. Typical investigation takes 14-30 days depending on complexity and the affected system. We’ll provide status updates at least every 14 days throughout the investigation.
04

Remediation & Verification

Once validated, Penva Security will implement remediation and notify you when fixes are deployed. You’re welcome (and encouraged) to verify the remediation with non-destructive testing aligned to the original report scope.
05

Coordinated Public Disclosure (optional, by mutual agreement)

Where appropriate, Penva Security supports coordinated public disclosure of confirmed vulnerabilities after remediation. Standard coordination window is 90 days from initial report, extendable by mutual agreement.
Scope

What's In Scope and What Isn't

Clear scope helps everyone. Anything in-scope is welcomed under this policy; out-of-scope items have other appropriate channels.

Allowed

Welcome Under This Policy

Not allowed

Other Channels Apply

Safe Harbour

Protection for Good-Faith Researchers

Safe Harbour

Protection for Good-Faith Researchers

Good-faith research is protected

Penva Security commits to safe harbour for good-faith security research conducted within the scope of this policy. We will not initiate legal action against researchers who: act in good faith to identify and report vulnerabilities, stay within the in-scope systems above, avoid destructive testing or accessing data beyond what’s necessary to demonstrate the issue, and report findings to Penva Security before public disclosure.

What’s outside safe harbour: intentional data exfiltration, social engineering of staff, denial-of-service attacks, attempting to access other users’ data, public disclosure before coordinated disclosure window, and any activity that violates Australian or applicable law beyond authorised security research.

If you’re unsure whether something falls within scope or safe harbour, ask us first via the same security contact – we’d rather have a conversation upfront than navigate ambiguity later.

Contact

How to Reach Penva Security

One email address handles all disclosure reports. We commit to 48-hour acknowledgement during Australian business hours.

Security contact

How to Reach Penva Security

One email address handles all disclosure reports. We commit to 48-hour acknowledgement during Australian business hours.
Email vulnerability reports to the address below. PGP encryption available for sensitive reports – the key is referenced in our security.txt file.
FAQ

Disclosure Policy — Common Questions

Direct answers to the questions security researchers ask. Updated May 2026.

Do you have a bug bounty program?
Not currently. Penva Security welcomes good-faith security research under coordinated vulnerability disclosure but does not currently offer monetary rewards. We acknowledge reporters publicly (with consent) and provide credit in any post-remediation disclosure. We may launch a formal bounty program in future – if you’d like to be notified when we do, mention it in your initial report.
What scope is acceptable for testing without explicit permission?
Non-destructive, good-faith testing of internet-exposed Penva Security systems for the purpose of identifying vulnerabilities to report under this policy is acceptable. This includes web application testing, API testing, configuration review, and observation of behaviour. Out of scope: anything that would degrade availability, exfiltrate non-trivial amounts of data, attempt social engineering, or access other users’ data.
How does Penva Security treat researchers in good standing?
Researchers who report vulnerabilities under this policy in good faith are treated as trusted contributors. We do not pursue legal action against good-faith researchers for activities reasonably consistent with this policy. We commit to: acknowledging discovery, providing updates, crediting the reporter (with consent), and acting on the report in good faith.
What's your encryption / PGP key for sensitive reports?
Our PGP public key for the [email protected] email address is referenced in our security.txt file at https://penvasecurity.com.au/.well-known/security.txt. The security.txt file is the machine-readable counterpart to this human-readable policy, aligned to RFC 9116.
What happens if I find a vulnerability in a Penva Security client's system, not Penva Security itself?
Report it to the affected client directly. Most modern organisations have their own responsible disclosure or bug bounty programs – check their /security.txt file or website. Don’t report Penva Security clients’ vulnerabilities to Penva Security – we cannot act on those reports and they’re outside the scope of this policy. We respect the confidentiality of every engagement we’ve conducted.
Will you publish a CVE for valid findings?
For vulnerabilities affecting Penva Security’s own custom software or systems, yes – we can coordinate CVE assignment through MITRE or a CNA where appropriate. For configuration issues, third-party software vulnerabilities, or issues that don’t warrant a CVE, we’ll work with you on appropriate disclosure timing without CVE assignment.
Do you accept reports about vulnerabilities in your published security research?
Yes – if you find errors, misrepresentations, or out-of-date information in Penva Security’s published security research (blog posts, whitepapers, glossary entries), please report them via the same channel. We’ll correct the record and credit the report as appropriate. Accuracy of our published material is a security-equivalent concern.
What if my report is rejected or you disagree about severity?
We’ll explain our reasoning and engage in good-faith discussion. Severity assessments can be subjective and we welcome disagreement. If we can’t reach agreement, you may consider escalating through coordinated disclosure bodies (CERT Australia, ASD’s ACSC). We commit to professional engagement throughout.
Next step

Reporting a Vulnerability? Email [email protected]

48-hour acknowledgement during Australian business hours. PGP encryption available for sensitive reports via the key referenced in our security.txt file.

Reporting a Vulnerability? Email [email protected]

48-hour acknowledgement during Australian business hours. PGP encryption available for sensitive reports via the key referenced in our security.txt file.