Definitions
"Vulnerability" means a security weakness in PDL systems, software, or infrastructure that could be exploited to compromise confidentiality, integrity, or availability.
"Responsible Disclosure" means reporting a Vulnerability to PDL in good faith before public disclosure, allowing PDL time to remediate.
"Safe Harbor" means PDL's commitment not to pursue legal action against good-faith reporters complying with this Policy.
"Embargo Period" means the period during which a reporter agrees not to publicly disclose a Vulnerability while PDL remediates.
"In-Scope Systems" means PDL production systems, APIs, web properties, and software products as further defined herein.
"Out-of-Scope Systems" means third-party services used by PDL, PDL personnel's personal accounts, and other systems not owned or operated by PDL.
Responsible Disclosure Commitment
PsyData Labs L.L.C. encourages responsible disclosure of security vulnerabilities. PDL will not pursue legal action against individuals who discover and report security vulnerabilities in good faith and in compliance with this Policy. PDL commits to acknowledging reports, communicating investigation status, and coordinating responsible disclosure.
In-Scope and Out-of-Scope Systems
In-Scope: PDL production systems, APIs, web properties at https://www.psydata.net and related subdomains, mobile applications, and PDL-operated services.
Out-of-Scope: Third-party services integrated with PDL platforms; PDL personnel's personal accounts; upstream open-source components (report to applicable upstream project); PDL customer systems not operated by PDL.
Reporting Procedure
Security vulnerabilities must be reported to: PsyData Labs Security Team, security@psydata.org. Reports should include:
A clear description of the vulnerability;
Steps to reproduce the issue;
Assessment of potential impact;
Any proof-of-concept code (non-malicious). 14. Response Timelines
Stage Target Timeline
Acknowledgment of receipt [X] business days
Initial assessment & status update [Y] business days
Remediation timeline communicated [Z] business days
Target resolution [REMEDIATION TIMELINE — TBD by severity] 15. Safe Harbor
PDL grants Safe Harbor to reporters who: (a) act in good faith; (b) do not exploit the Vulnerability beyond what is necessary to demonstrate the issue; (c) do not access or exfiltrate user data; (d) do not perform denial-of-service attacks; (e) do not engage in social engineering; and (f) comply with the Embargo Period. Safe Harbor is not available to reporters who violate these conditions.
Prohibited Actions by Reporters
Exploitation of the Vulnerability beyond proof-of-concept demonstration;
Accessing, downloading, or exfiltrating user data;
Denial-of-service attacks;
Social engineering of PDL personnel;
Physical attacks on PDL infrastructure;
Public disclosure before PDL's Embargo Period expires.
Disclosure Timeline
PDL requests a coordinated Embargo Period of ninety (90) days from the date of report acknowledgment, unless otherwise agreed in writing. PDL will endeavor to patch the Vulnerability within the Embargo Period. Following patching, PDL may publish a security advisory acknowledging the Vulnerability and, with reporter's consent, crediting the reporter.
Researcher Credit
PDL may acknowledge responsible reporters in security advisories with the reporter's prior consent. PDL makes no guarantee of public recognition and provides no financial compensation for vulnerability reports absent a separately executed bug bounty agreement.
19–27. (See General Policy Terms)
Governing law, contact, and standard legal provisions: Madison County, New York State, United States. Contact: legal@psydata.org | https://www.psydata.net.