Reporting a Vulnerability
Email support@pronovatech.com with “Security” in the subject line. That mailbox is monitored, and the subject line is what routes a report out of the general support queue.
A machine-readable copy of this contact is published at /.well-known/security.txt in the format defined by RFC 9116.
What to include. A report we can reproduce is worth far more than a scanner result:
- The component and version — portal, agent, service, relay, or Pro Console — and where you found it.
- Steps to reproduce, and what you observed versus what you expected.
- What an attacker gains: whose data, which devices, what privilege.
- Any proof-of-concept, log excerpt or capture that shows the behaviour.
What we ask of you while you are testing:
- Test only against accounts and devices you own or are explicitly authorised to test. Do not access, modify or retain another customer's data, and do not connect to a device you were not given.
- Do not run denial-of-service, spam or high-volume automated traffic against the portal or the relays.
- Do not use social engineering or physical intrusion against our staff or customers.
- Give us a reasonable opportunity to fix the issue before you publish it, and tell us the date you intend to publish so we are not surprised by it.
What we commit to. We will acknowledge every report sent to the address above, we will tell you whether we consider it a vulnerability and why, and we will tell you when a fix has shipped. If we disagree with your assessment we will say so and give our reasoning rather than going quiet.
We do not publish a response-time target. That is a deliberate omission rather than an oversight: we would rather state no figure than one we have not committed to internally. If timing matters to your disclosure schedule, say so in your first email and we will agree dates with you directly.
There is no bug bounty. We do not currently pay for vulnerability reports, and there is no reward programme to enrol in. We will credit you by name in the release notes for the fix if you want that, and will leave you out of them if you do not.
What this page is not. It is not a licence to test, and it is not a legal safe harbour — we are not in a position to bind third parties whose systems your testing might touch, including the sub-processors listed in section 2. It is a statement that a good-faith report made under the conditions above will be treated as a good-faith report.