VDP Public Statement

PsyData Labs L.L.C. is committed to the security of its systems and the protection of users. PDL invites external security researchers and the public to report potential vulnerabilities through this Vulnerability Disclosure Policy. PDL is committed to working with good-faith researchers to understand and address security concerns.

Scope

In-Scope Systems: PDL production web applications and APIs; PDL-operated developer portals; authentication systems operated by PDL; PDL mobile applications; and infrastructure directly operated by PDL.

Out-of-Scope: Third-party services used by PDL but not operated by PDL; PDL personnel's personal accounts and devices; denial-of-service testing; social engineering attempts; automated vulnerability scanning without prior authorization.

Submission Guidelines

Submissions must:

Be clear, detailed, and reproducible;
Include steps to reproduce, observed and expected behavior, and impact assessment;
Not include actual user data;
Relate to an In-Scope system.
Duplicate reports, out-of-scope reports, and theoretical vulnerabilities without demonstrated impact may not receive response.

CVE Coordination

For significant vulnerabilities, PDL may coordinate with MITRE or CISA for CVE assignment. PDL will communicate CVE coordination status to reporters during the disclosure process. Researchers who independently wish to pursue CVE assignment are requested to coordinate with PDL first to avoid duplicate assignments.

Patch and Advisory Timeline

PDL targets patching within [REMEDIATION TIMELINE — TBD based on severity] from acknowledgment. A public security advisory will be published following patch deployment. Advisory content will be coordinated with the reporter where feasible.

Bug Bounty

Bug bounty program status: [PENDING — To Be Determined]. No financial compensation is promised or implied by this VDP without a separately executed bug bounty agreement. PDL reserves the right to establish a formal bug bounty program in the future. Researchers who submit reports under this VDP do not acquire any right to compensation by virtue of submission alone.

Legal Safe Harbor

PDL will not initiate legal action against researchers who comply with this VDP, including compliance with scope limitations, prohibition on data access, prohibition on service disruption, and compliance with the Embargo Period. Safe Harbor does not extend to exploitation, data exfiltration, or violations of this VDP.

17–27. (See General Policy Terms)
Contact: PsyData Labs Security Team, security@psydata.org | legal@psydata.org | https://www.psydata.net. Governing law: Madison County, New York State, United States.

Document Metadata