Reporting an issue
Keep your report concise, add steps to reproduce, and include a proof of concept if possible. We acknowledge valid reports within 48 hours of receipt. Avoid following up more than once every 72 hours, so the team can focus on fixing the issue.Bounties
We pay a bounty to security researchers who have followed this policy and found a confirmed high-severity vulnerability. Amounts are decided case by case.What you must not do
- Break any applicable law or regulation
- Access unnecessary, excessive, or significant amounts of data
- Modify data in Plain systems or services
- Use high-intensity invasive or destructive scanning tools to find vulnerabilities
- Attempt or report any form of denial of service, for example overwhelming a service with a high volume of requests
- Disrupt Plain services or systems
- Submit reports detailing non-exploitable vulnerabilities, or reports arguing that a service does not fully align with “best practice”, for example missing security headers
- Submit reports detailing TLS configuration weaknesses, for example “weak” cipher suite support or the presence of TLS 1.0 support
- Communicate any vulnerability or associated detail by any means other than those described in this policy
- Social engineer, phish, or physically attack Plain staff or infrastructure
- Demand financial compensation in order to disclose a vulnerability, or threaten public disclosure of a vulnerability unless payment is made
What you must do
- Comply with data protection rules, and do not violate the privacy of any data Plain holds. Do not share or redistribute data retrieved from Plain systems or services, and do not leave it unsecured
- Securely delete all data retrieved during your research as soon as it is no longer needed, or within 1 month of the vulnerability being resolved, whichever comes first, or as otherwise required by data protection law
What Plain commits to
If you follow this policy when reporting an issue, we commit to:- Not pursuing or supporting any legal action related to your research
- Working with you to understand and resolve the issue, including an initial confirmation of your report within 48 hours of submission

