Security and disclosure
Last updated 18 September 2026
If you have found a security problem in anything we run or publish, we want to hear about it.
How to report
Email [email protected] with "Security" in the subject. Include what you found, where, and the steps to reproduce it. If you need to send something sensitive, say so and we will arrange a secure channel.
What we will do
- Acknowledge your report within three working days.
- Tell you our assessment, and a fix timeline, within ten working days.
- Credit you when the fix ships, if you would like that.
Scope
In scope: palworks.ai, our Chrome extensions, our web apps, and the services we operate for clients. Out of scope: reports that only describe a missing best practice with no demonstrated impact, volumetric denial of service, and social engineering of our people or our clients.
Good faith
We will not pursue legal action against you for research carried out in good faith under this policy: stay within scope, do not access or modify other people's data, do not degrade a live service, and give us a reasonable chance to fix the issue before you publish.
Our own practice
- Every service we operate is monitored for uptime, certificate expiry and domain expiry.
- Secrets live outside source control.
- Sites we host are served over HTTPS with certificates renewed automatically.
PALWORKS