security policy
security policy.
How to report a vulnerability, what's in scope, and what we commit to when you do.
Reporting a vulnerability
Applies to withpilar.com (marketing website) and app.withpilar.com (Pilar application). Sections that apply only to one are noted.
Email [email protected] with a description of the vulnerability, steps to reproduce, and — if you have them — proof-of-concept payloads or screenshots.
We aim to acknowledge reports within 48 hours and to remediate high-severity issues within 30 days.
A machine-readable version of this policy is published at /.well-known/security.txt per RFC 9116.
Scope
In scope:
- —withpilar.com
- —app.withpilar.com
Out of scope: third-party vendors (Cal.com, Supabase, Vercel, Railway, Resend, Cloudflare). Please report vulnerabilities in those services directly to the vendors.
What we ask
To keep testing safe for real users and to give us a fair chance to fix issues, we ask that you:
- —Do not publicly disclose the vulnerability before we have had a reasonable opportunity to fix it
- —Do not test on real user accounts — create your own test signup for testing
- —Do not run automated scans that generate high traffic volumes against production
- —Do not access, modify, or destroy user data
- —Do not attempt social engineering of Pilar employees, contractors, or partners
What we offer
Pilar is an early-stage company. We cannot yet offer a paid bug bounty program. We will:
- —Acknowledge receipt within 48 hours
- —Provide status updates as we investigate and remediate
- —Credit you in a public acknowledgments list once the issue is fixed, unless you prefer to remain anonymous
- —Not pursue legal action against researchers who follow this policy in good faith
Out of scope issues
The following do not qualify as vulnerabilities under this policy:
- —Missing security headers with no demonstrated impact
- —Social engineering, phishing, or physical attacks
- —Denial-of-service attacks
- —Reports from automated scanners without a working proof-of-concept
- —Rate-limiting or spam prevention concerns on public forms
- —Best-practice suggestions without a demonstrated vulnerability
Contact
Security reports: [email protected]
Machine-readable policy: /.well-known/security.txt