Back

Vulnerability disclosure

Help us keep Planar secure.

We welcome reports from customers and security researchers. If you believe you have found a vulnerability in a Planar-operated service, email us with enough detail to investigate it safely.

security@planar.so

What to include

Identify the affected service or asset, the suspected impact, reproduction steps, and the minimum evidence needed for us to validate the issue. Please include a reliable way to contact you for follow-up.

Testing guidelines

  • Limit testing to Planar-operated public services.
  • Use only the minimum testing needed to demonstrate the vulnerability.
  • Stop and report immediately if you encounter customer, personal, or confidential data. Do not retain, alter, delete, or disclose it.
  • Do not disrupt service, degrade availability, establish persistence, use social engineering or physical attacks, or send excessive automated traffic.
  • Do not publicly disclose an unresolved issue without coordinating with us.

If you are unsure whether planned testing is covered, contact us before you begin.

Safe harbor

Planar authorizes good-faith security research that follows this policy and will not initiate legal action against you for that research. This commitment cannot bind third parties or excuse activity outside this policy or applicable law.

What to expect

We review good-faith reports promptly, acknowledge credible reports, and may ask for clarification or a reasonable period to investigate and remediate before public disclosure. We coordinate public disclosure when appropriate, but do not promise a fixed acknowledgement or remediation deadline.

This is a responsible disclosure program, not a paid bug bounty. Planar does not promise payment or other rewards.

  • Privacy·
  • Terms·
  • Security·
  • © 2026 Planar