Security
Vulnerability Disclosure Policy
How to responsibly report a security vulnerability in PawOS.
Last updated: 31 August 2026
1. Scope
This policy covers the PawOS desktop application, the pawos.revantaai.com website, and the backend services described in our Security Policy.
2. How to report
Email security@revantaai.com with steps to reproduce the issue, its potential impact, and any proof-of-concept material. Please avoid public disclosure until we've had a reasonable opportunity to address the issue.
3. Our commitment
We aim to acknowledge reports as promptly as we reasonably can and to keep you informed of remediation progress. We do not currently operate a paid bug-bounty program.
4. Safe harbor
Good-faith security research conducted consistent with this policy will not result in legal action from us, provided it avoids privacy violations, data destruction, service disruption, and access to data beyond what is necessary to demonstrate the vulnerability.
5. Out of scope
Social engineering against our staff, physical attacks against our facilities or personnel, and denial-of-service testing are out of scope for this policy and should not be attempted.
6. Contact
General questions about this document: legal@revantaai.com. Privacy and data-protection requests: privacy@revantaai.com. Security reports: security@revantaai.com, following our Vulnerability Disclosure Policy. See also our Grievance Officer contact above where this document includes one.