pearlblack Security & Trust Center Trust Center ↑

Vulnerability Disclosure Policy.

We welcome good-faith security research into our products and this website, and we commit to working with reporters respectfully and promptly.

How to report

Email security@pearlblack.co. Please include: a description of the issue, the affected component or URL, reproduction steps or proof of concept, the potential impact as you understand it, and how you would like to be credited or contacted.

Scope

In scope: this website (pearlblack.co), the Security & Trust Center (security.pearlblack.co) and published pearlblack software artifacts. Out of scope: third-party services we do not operate, social engineering, physical attacks, and denial-of-service testing.

Safe testing boundaries

Do not access, modify, or exfiltrate data that is not yours. Use the minimum data necessary to demonstrate the issue. Stop and report immediately if you encounter personal data. Do not degrade service availability. Do not run automated high-volume scanning against production surfaces. Testing that follows these boundaries in good faith will not be met with legal escalation by us; activity outside them may be.

What happens after you report

We acknowledge reports within two business days and complete initial triage within five business days. For material findings that remain open, we provide a status update at least every ten business days. We assess severity, preserve evidence, mitigate, and remediate based on severity, exploitability, and operational consequence. These are our internal operating targets, not contractual commitments.

Coordinated disclosure

We ask that you give us reasonable time to remediate before public disclosure and that we agree on the disclosure timing together. We are glad to credit reporters who wish to be named. A report is closed when the fix is confirmed, the reporter is informed, and the record is preserved.

Confidentiality

Report contents are handled as security-sensitive information. We minimize who sees them and we log their handling.