Security disclosure policy

Responsible disclosure for P31 Labs, Inc. public surfaces and open-source repositories.
Effective date: 2026-05-01. Machine-readable: /.well-known/security.txt

1. Scope

In scope

The following surfaces are in scope for security reports:

Out of scope

2. How to report

Send your report to:

Email: [email protected]
Subject line: [security] <brief description>
Machine-readable contact: /.well-known/security.txt

We do not currently operate a formal bug bounty program and cannot promise financial rewards, but we do commit to acknowledging valid reports, coordinating on a fix timeline, and crediting researchers who want to be acknowledged (with their permission) in a public disclosure or changelog.

3. What to include in your report

A useful report includes:

Please limit your testing to what is necessary to demonstrate the vulnerability. Do not access, modify, or exfiltrate data beyond what is needed to prove the issue.

4. Response timeline

We are a small nonprofit team. We will be transparent with you about our capacity and timeline. If you do not receive an acknowledgment within 5 business days, please follow up.

5. Safe harbor

P31 Labs, Inc. extends the following good-faith safe harbor to security researchers who comply with this policy:

This safe harbor does not extend to attacks on third-party infrastructure (Cloudflare, Stripe, Google) or to conduct that violates third-party terms of service. We cannot authorize access to systems we do not own or operate.

6. Coordinated disclosure

We follow a coordinated disclosure model. This means:

Our default target for coordinated disclosure is 90 days from acknowledgment, consistent with common industry practice. For critical issues affecting live user data, we will aim for a shorter timeline.

7. Additional out-of-scope guidance

The following will not be treated as valid security reports under this policy:

8. Contact

P31 Labs, Inc.
EIN 42-1888158 — Georgia domestic nonprofit
Security email: [email protected] — subject line [security]
Machine-readable: /.well-known/security.txt
GitHub: github.com/p31labs — private advisories accepted via GitHub Security Advisory

© 2026 P31 Labs, Inc. — Privacy · Terms · Accessibility