Report a vulnerability
Send it to security@penv.cloud, with what to put in the message and the human acknowledgement you get within 2 business days.
Send it to security@penv.cloud. One address, read by a person.
What happens next
You get an acknowledgement within 2 business days, written by someone who read the report. That message names who is handling it and what they need from you. This page is where that commitment is made, so hold us to the wording here.
There is no bounty program and no bug bounty platform. There is a reply.
What to put in the message
What you found, in one sentence, and the address or the page it affects.
How to reproduce it. The exact request or the exact steps. A curl command with the value redacted is ideal.
What it gets an attacker. Reading another workspace's values is a different report from a missing security header, and saying which one you have is what gets it triaged correctly.
When you tested, with a timezone, and the workspace or the account you tested from. That is what lets us match your report to the entries in the log.
What not to send
Never send a live credential, whether it is yours or one you got hold of. Rotate it, then report the shape of it rather than the value. A report that carries a working credential creates a second incident on top of the first one.
Two more things to leave out.
Do not send another customer's values. If you can read them, say so and say how, then stop reading.
Do not attach a full database dump or a memory dump. Send the two lines that prove the finding, and we will ask if more is needed.
Testing leaves a record
Every read you perform lands an entry in the audit log naming the credential that made it, the address it touched, the time and the source IP. That record is what the affected workspace sees.
This works for you rather than against you. It is how a report gets confirmed in minutes instead of argued about, so tell us the window you tested in and we will read the same rows you did. See the record of who did what.
Test against a workspace you own. Reading a workspace you were not invited to is visible, attributed, and not something a report excuses after the fact.
Next: a credential leaked.