Tapestry PRMGet early access

Reporting a vulnerability

Effective 7 September 2026

If you find a security problem in Tapestry PRM or this website, please help us understand and address it.

How to reach us

Email security@tapestryprm.com with the affected surface, reproduction steps and likely impact. Please keep private data out of the initial message and do not publish an exploit or someone else’s information.

What to expect

We aim to acknowledge reports within three working days and provide an initial assessment within ten. These are response targets, not guaranteed service levels. We will keep you informed as we investigate and discuss appropriate credit with you. There is no paid bounty programme.

Good-faith research

Use your own installation, accounts and data. Avoid accessing, changing or retaining anyone else’s information, denial-of-service testing, high-volume scans and social engineering. If you encounter private information unintentionally, stop and tell us. Give us reasonable time to investigate and fix an issue before disclosure.

We will not pursue legal action against research conducted in good faith under this guidance. We cannot authorise testing of another organisation’s systems or bind third parties.

Scope and impact

Reports may concern this website or Tapestry software provided for testing, including local services and source permissions. We assess issues by their demonstrated impact, including exposure of local data. A local architecture does not remove the need for secure storage, permissions and deletion.

Machine-readable contact

Our contact is also available at /.well-known/security.txt.