Skip to content
Explore Pillion
Security

What we commit to, and how to tell us we broke it.

The commitments below are contract terms, not aspirations: they appear in the security addendum attached to every paid agreement. The reporting path is open to anyone, customer or not.

Report a vulnerability
info@pillion.dev
Human reply within 72 hours, weekends included.
Encrypted reports
PGP accepted. Attachments up to 25 MB.
Not for support
info@pillion.dev · Support and abuse
Machine readable
/.well-known/security.txt

The commitments

EncryptionGit objects, LFS blobs, Postgres and backups encrypted at rest; TLS 1.3 in transit.Continuous
Key handlingCustomer secrets envelope-encrypted under a per-owner key. Secret values are never written to logs.Rotated every 90 days
Operator accessNo standing access to customer repositories. Production access is break-glass, time-boxed to four hours.4-hour ceiling
Change controlEvery production change arrives through a reviewed pull request with a second approver.Two-person rule
BackupsPoint-in-time recovery for Postgres and the Git write-ahead log, with restore drills in allowed geography.RPO 5 min · RTO 4 h
CertificationControls are mapped against ISO 27001 Annex A. We hold no certificate today.Not yet certified

Coordinated disclosure

Report in good faith and stay inside the rules and we will not pursue legal action, will not report you, and will credit you if you want it. There is no bounty programme yet.

72 hours
First human response, with a named owner on our side.
7 days
Triage decision, severity, and a fix window you can hold us to.
90 days
Default disclosure window. We will ask for more only with a reason.
On fix
Advisory published, credit given if you want it.

Severity and the clock it starts

CriticalCross-tenant read or write, authentication bypass, remote code execution on the data plane.24 hours
HighPrivilege escalation inside an organization, secret disclosure, ruleset bypass on a protected ref.7 days
MediumStored cross-site scripting behind authentication, missing authorization on a low-value endpoint.30 days
LowInformation leaks with no practical path to data, hardening gaps, missing headers.Next release