Lindoby Petrarch
Sign in

Reporting a vulnerability

Send it here

founders@petrarch.co

It reaches the founders directly. Include what you did, what you saw, and enough to reproduce it. If you are unsure whether it is a vulnerability, send it anyway.

No PGP key: treat this address as ordinary mail. Too sensitive for plaintext? Say so in one line and we will arrange another channel.

In scope
  • The application and its API, on the host this page is served from.
  • Anything that crosses the isolation boundary between two workspaces.
  • Anything that reaches document text without writing the audit row that the read requires.
  • Anything that lets a Petrarch account reach a customer workspace without a live grant.

The product is invitation-only. Write to us and say what you want to test.

Out of scope
  • Denial of service, load testing, and anything that degrades the service for other people.
  • Social engineering of our staff or our vendors, and physical access.
  • Scanner output with no demonstrated impact, including missing headers and version banners.
  • Findings in our vendors' products. Report those to them; tell us too and we will follow up.
  • Reports about the marketing site or other Petrarch properties, which this policy does not cover.
What you can expect
commitments from people, not controls

Everything else on these pages is a property of the code. This section is what a small team undertakes to do.

Acknowledgement within three business days
From a person, not an autoresponder. The address reaches a small team.
An assessment within ten business days
The impact, whether we agree it is a vulnerability, and when we intend to fix it. If we disagree we say so.
We tell you when it is fixed
Credited by name or handle if you want that, or not if you do not.
No legal action for good-faith research
Stay inside this policy, stop as soon as you reach data that is not yours, tell us, and do not keep it.
What we ask of you
  • A reasonable chance to fix it before you tell anyone else. We will not sit on it.
  • Do not access, modify, download or keep data that is not yours. If you reach some, stop, tell us, delete it.
  • Nothing that degrades the service for other people, and no testing against a customer's workspace.
  • One report per finding, in English, detail in the mail rather than behind an expiring link.
The machine-readable version

Published at https://lindo.petrarch.co/.well-known/security.txt in RFC 9116 format.

Trust and securitySubprocessorsData processingWhere it runs