// SECURITY

Responsible Disclosure

Last updated: June 2026

Security is what we do, so we hold our own systems to the same standard we hold our clients' to. We value the work of security researchers, and we welcome reports of vulnerabilities in our website and systems. This page explains how to report something to us, what's in scope, and what you can expect from us in return. If you're acting in good faith and follow this policy, we'll work with you — not against you.

// REPORT A VULNERABILITY

Email security@penlabs.co.za with the details below. We aim to acknowledge every report within 3 business days.

[Set up this mailbox, or change it to your preferred address. A monitored inbox matters here.]

1. What's in scope

This policy covers digital assets that we own and operate, namely:

  • Our website. penlabs.co.za and its subdomains.
  • Our email and account infrastructure. Where it is operated by us. [Adjust if you host elsewhere.]

If you're not sure whether something is in scope, ask us first at security@penlabs.co.za before you start testing.

2. What's out of scope

To protect our staff, our clients, and third parties, the following are not authorised under this policy:

  • ×Anything belonging to our clients, or systems we test on their behalf — those are governed by separate, signed engagement agreements.
  • ×Third-party services we use but don't control (our host, email provider, and similar). Report those to the relevant vendor.
  • ×Social engineering, phishing, or vishing of our staff, contractors, or clients.
  • ×Physical attacks against our premises, people, or equipment.
  • ×Denial-of-service (DoS/DDoS), load testing, or anything that degrades or disrupts our services.
  • ×Spam, brute-force, credential stuffing, or high-volume automated scanning.
  • ×Accessing, modifying, or deleting data that isn't yours.
  • ×Reports with no realistic security impact (e.g. missing security headers with no demonstrable exploit, version disclosure, theoretical issues).

3. Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we'll work with you to understand and resolve the issue quickly, and we will not pursue or recommend legal action against you in connection with it. If a third party brings legal action against you for activity that complied with this policy, we'll make it known that your actions were authorised.

This safe harbour applies only to legal claims under our control, and is subject to our own compliance with applicable South African law. To qualify, your disclosure must be unconditional — it may not involve extortion, threats, or any demand for payment as a condition of telling us about the issue.

4. Guidelines for your research

To stay within good faith and this policy, please:

  • Report any vulnerability you discover as soon as you reasonably can.
  • Only test against systems in scope, and respect the out-of-scope list.
  • Use the minimum interaction needed to prove a vulnerability exists — don't go further than a proof of concept.
  • Stop immediately and tell us if you encounter any personal information, client data, or other sensitive data, and don't save, copy, or share it.
  • Avoid privacy violations, data destruction, and any disruption to our services.
  • Give us a reasonable amount of time to investigate and fix the issue before you disclose it publicly, and coordinate any public disclosure with us first.

5. How to report, and what to include

Send your report to security@penlabs.co.za. The more detail you give us, the faster we can confirm and fix it. Please include:

  • A clear description of the vulnerability and the system or URL affected.
  • Step-by-step instructions to reproduce it.
  • The potential impact — what could an attacker do with it?
  • Any proof-of-concept code, screenshots, or request/response logs that help (redact any sensitive data).
  • How we can contact you, and whether you'd like to be credited.

You may report anonymously, though it's harder for us to follow up or credit you if you do.

6. What you can expect from us

When you report in line with this policy, we will:

  • Acknowledge. Confirm we've received your report within 3 business days.
  • Investigate. Validate the issue and keep you reasonably updated on our progress.
  • Fix. Work to remediate confirmed vulnerabilities as quickly as our resources allow, prioritised by risk.
  • Credit. With your permission, acknowledge your contribution once the issue is resolved. [Optional: maintain a public thanks / hall-of-fame list.]

7. Rewards

This is a responsible disclosure policy, not a paid bug-bounty programme. We don't currently offer monetary rewards, but we deeply appreciate every good-faith report and will gladly credit you for your help. [If you decide to offer rewards later, update this section.]

8. security.txt

Our machine-readable security contact details are published, following RFC 9116, at /.well-known/security.txt.