← Legal Center

Effective and last updated October 4, 2026

Security & Responsible Disclosure Policy

Rules for reporting security vulnerabilities safely and responsibly.

Applies to: Users and security researchers

Reporting

Report suspected vulnerabilities to legal@pyramad.com with affected URLs or features, reproduction steps, impact, and supporting evidence. Do not include unnecessary personal data, credentials, or secrets. We will acknowledge and assess reports as resources and risk permit.

Good-faith research

  • Avoid accessing, changing, deleting, or retaining data that is not yours.
  • Do not disrupt availability, degrade systems, use denial of service, spam, social engineering, or physical attacks.
  • Use the minimum testing needed to demonstrate an issue and stop if you encounter sensitive information.
  • Allow reasonable time for investigation and remediation before public disclosure.
  • Do not demand payment or threaten disclosure; any recognition or reward is discretionary unless a written program says otherwise.

Scope and safe harbor

This policy does not authorize testing of third-party services, customer sites, employee devices, or physical facilities. Pyramad intends not to pursue legal action for good-faith research that follows this policy, but cannot bind third parties or excuse violations of law.

Customer responsibilities

Customers remain responsible for their project configuration, access permissions, third-party integrations, generated code review, secret handling, backups, monitoring, and response procedures appropriate to their use.

Legal contact: legal@pyramad.com

These policies should be read together. A signed project agreement controls where it expressly says so.

THE NEXT THING STARTS HERE

What will you
bring to life?

Start building for free
PYRAMAD®   /   MAKE WHAT MATTERS