Paprel · Legal
Vulnerability Disclosure Program
Responsible disclosure · No monetary rewards
Last updated: 9 September 2026
We welcome good-faith reports that help protect Paprel and its customers. Send suspected security issues to security@paprel.com. Read these boundaries before taking further action.
1. Report privately with minimal evidence
Email security@paprel.com with the affected service or URL, when you observed the issue, potential impact and minimal reproduction steps. Use redacted examples and synthetic data. Do not email passwords, tokens, personal data or confidential customer records. If sensitive evidence is necessary, ask us to arrange a secure transfer first.
2. Obtain written testing authorisation
This program accepts reports about Paprel-operated websites and services; it does not grant permission to test them. Before active testing, obtain Paprel’s express written approval identifying the assets, accounts, methods and testing period. Account ownership or sandbox access alone is not testing authorisation. Customer applications, customer-operated embedded deployments, other tenants, integrations and third-party infrastructure are outside Paprel’s authorisation. If ownership or scope is unclear, ask before proceeding.
3. Keep testing within safe boundaries
Stay within the written scope and use only approved test accounts and synthetic data. Do not access others’ accounts or records; extract data; alter real financial records; introduce malware or persistence; or use phishing, social engineering, credential attacks, denial-of-service, destructive techniques or high-volume automated scanning. Stop immediately if testing affects availability or exposes non-public data. Do not continue to establish additional impact; report what happened privately.
4. Protect data and coordinate disclosure
Do not copy, retain or share non-public data beyond the minimum needed to report the issue securely. Protect any inadvertently obtained evidence and coordinate its secure deletion with us, subject to lawful preservation requirements. Give us a reasonable opportunity to investigate and remediate before publishing vulnerability details, and coordinate timing with us. Never publish credentials or customer data. Nothing here restricts disclosures required or protected by applicable law or reports to competent authorities.
5. No bounty, payment or response guarantee
This is a disclosure program, not a bug bounty. Paprel offers no prize money, cash rewards, bounties or other financial awards under this program.A report creates no entitlement to payment, reimbursement, recognition, employment or a commercial engagement. We assess validity, severity, remediation priority and any voluntary recognition at our discretion. No acknowledgement, fix, update or resolution deadline is promised; this does not limit duties imposed by applicable law or an existing agreement.
6. Limited protection for authorised research
For good-faith research within Paprel’s express written authorisation and these conditions, Paprel will not initiate legal action solely for that authorised testing. This does not excuse activity outside that scope, waive claims for other conduct, bind customers, providers or authorities, or grant immunity under law. We may require testing to stop or change scope prospectively; doing so does not retrospectively remove this protection for earlier compliant authorised testing. Continue to comply with applicable law and third-party rights.