Security contact
Found something? Email us. We will reply within two business days, we will not threaten you, and we will tell you when it is fixed.
Effective: 2026-08-24 · Last updated: 2026-08-24
Reporting a vulnerability
Email info@pilebase.io with "Security" in the subject line. It reaches one person, who is also the person who will fix it.
Tell us what you found and how to reproduce it. A rough description is more useful than nothing, so please do not hold back because the write up is not polished.
What we promise you
- A reply from a person within two business days, and normally much sooner.
- We will tell you what we found when we looked, and whether we agree it is a problem.
- We will tell you when it is fixed.
- We will not take legal action against you for research done in good faith under the rules below, and we will not ask your employer or your internet provider about you.
- We will credit you if you want to be credited, and keep you out of it if you do not.
We have no money, so there is no bug bounty. We will say thank you properly and mean it.
What we ask of you
- Only test against your own account and your own data. Do not access, change or keep anybody else's.
- Do not run anything that degrades the service for other people: no denial of service, no load testing, no mass automated scanning.
- Do not social engineer anyone, and do not go after the physical premises.
- Give us a reasonable chance to fix it before you publish. We will not use that as a way to sit on it, and if we are being slow, say so.
- If you come across somebody else's personal data by accident, stop, and tell us. Do not download it, and do not keep a copy.
In scope
pilebase.ioand everything under it.- The public demonstration instance, which carries fictional data only.
- Any Pilebase subdomain belonging to a supply yard, with the important caveat that the data on those belongs to that business and its customers, not to us. Treat it with more care, not less.
Out of scope
- Anything hosted by somebody else. Reports about our hosting provider, our email provider or our payment provider should go to them.
- Findings with no security impact: a missing header that changes nothing, software version disclosure, a self reported scanner result with no working proof.
- Social engineering, phishing and physical access.
Some things worth knowing before you look
Said here so nobody spends an afternoon on a finding we already know about.
- Payments are switched off. There is no live payment path on this site, and no live payment keys exist.
- Text messages and automated calls to businesses are switched off, deliberately, by configuration.
- Passwords are hashed with scrypt and checked against known breached password lists. Session and link tokens are stored as hashes, never in the clear.
- The service worker caches no API response. That is enforced by an empty allowlist, not by convention.
- Outbound requests to addresses a user supplies are filtered against private, loopback, link local and reserved ranges, at the moment of the request and not only when the address was saved.
Contact
Email info@pilebase.io. Related: our privacy policy covers what we hold and for how long.