Skip to content

Security: Pinvou/pinvou-agent

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest published Community release and the current main branch. Older releases may not receive backports.

Report a vulnerability

Use GitHub Private Vulnerability Reporting as the primary reporting channel. If that is not available, email security@pinvou.com.

Include the affected version, reproduction steps, and potential impact when possible. Include only the minimum data needed to reproduce the issue, and remove unrelated personal, customer, or credential data.

Do not open a public issue or discussion for an unpatched vulnerability, including suspected credential exposure, remote execution, authorization bypass, or cross-user data access.

Disclosure process

Reports are reviewed on a best-effort basis. Pinvou does not currently promise a response-time SLA or operate a vulnerability bounty program. When a report is confirmed, we will work with the reporter on a reasonable disclosure timeline and publish a fix or mitigation before public technical details when practical.

Do not test against systems or data you do not own or have permission to use.

There aren't any published security advisories