Reporting a vulnerability
If you find a security problem in Tapestry PRM or this website, please help us understand and address it.
How to reach us
Email security@tapestryprm.com with the affected surface, reproduction steps and likely impact. Please keep private data out of the initial message and do not publish an exploit or someone else’s information.
What to expect
We aim to acknowledge reports within three working days and provide an initial assessment within ten. These are response targets, not guaranteed service levels. We will keep you informed as we investigate and discuss appropriate credit with you. There is no paid bounty programme.
Good-faith research
Use your own installation, accounts and data. Avoid accessing, changing or retaining anyone else’s information, denial-of-service testing, high-volume scans and social engineering. If you encounter private information unintentionally, stop and tell us. Give us reasonable time to investigate and fix an issue before disclosure.
We will not pursue legal action against research conducted in good faith under this guidance. We cannot authorise testing of another organisation’s systems or bind third parties.
Scope and impact
Reports may concern this website or Tapestry software provided for testing, including local services and source permissions. We assess issues by their demonstrated impact, including exposure of local data. A local architecture does not remove the need for secure storage, permissions and deletion.
Machine-readable contact
Our contact is also available at /.well-known/security.txt.