We welcome reports from security researchers and the wider community. If you believe you have found a security issue, email security@petsenseai.com with a clear description, reproduction steps, affected URLs, and any proof-of-concept material. PGP is available on request. Our machine-readable policy is published at /.well-known/security.txt in line with RFC 9116.
What to expect: we acknowledge new reports within 2 business days, provide an initial triage assessment within 5 business days, and send status updates at least every 10 business days until the issue is resolved. Please give us reasonable time to remediate before public disclosure. We will not pursue good-faith researchers who follow this policy, and we are happy to credit reporters in our acknowledgments once a fix has shipped.
Out of scope: denial-of-service testing, social engineering of our staff or users, physical attacks, automated scanner output without a working proof of concept, and issues in third-party services we do not operate.