Guidelines for How to Report a Vulnerability

- Familiarize yourself with the >> PI Coordinated Vulnerability Disclosure Policy.
- Use >> this form to report any potential vulnerabilities.
- We strive to respond promptly. Please engage in a constructive dialogue with us.
- Only demonstrate the existence of a vulnerability to the extent necessary. Avoid altering configurations or disrupting the normal operation of a production system, unless explicitly authorized.
- Obtain consent from PI before sharing information about identified vulnerabilities with any third party.
- Once the data for reporting a security issue is no longer needed, securely erase it to ensure it cannot be recovered.
Coordinated Disclosure Policy
In PI, we follow a four-step process for handling and disclosing vulnerabilities.
The steps include: 1) Reporting, 2) Analysis, 3) Handling, and 4) Disclosure.
1. Reporting
We encourage you to report any potential vulnerabilities in PI products and services within the defined scope. Please submit your report via the >> Report a vulnerability form.
While PI accepts anonymous reports, please note that if you choose to remain anonymous, we will be unable to communicate with you during the vulnerability disclosure process.
2. Analysis
PI will thoroughly investigate and attempt to reproduce the reported vulnerability, following our internal procedures. We will keep you informed of our progress and may request additional information during this process.
Once the vulnerability is confirmed, we will conduct a risk assessment to determine its severity level and evaluate potential impacts and consequences.
3. Handling
In case the vulnerability is confirmed, PI will proceed to define a remediation plan. The implementation of this plan will be prioritized based on the severity level and the evaluated impacts and consequences from the previous analysis.
Please note that for end-of-life products that are no longer supported, PI may only provide recommendations as we cannot offer remediations.
4. Disclosure
After resolving the reported vulnerability, PI will publish a Security Advisory.
PI follows a careful process when addressing vulnerabilities in our products and services. We strive to maintain a balance between transparency and allowing customers sufficient time to apply necessary fixes. As a result, the publication of advisories may be delayed to minimize potential customer impacts.
- Comply with the relevant laws and regulations.
- Do not exploit or take advantage of the vulnerability more than strictly necessary.
- Conduct product testing without any adverse impact on customers and individuals, or obtain before an explicit consent from them.
- Do not disrupt any PI’ service.
- Do not use high-intensity methods and invasive scanning tools.
- Take measures to prevent any negative impact on the safety or privacy of individuals.
- Do not access unnecessary, excessive, or significant amounts of data.
- Do not modify data in PI’ systems or services.
- Do securely delete all data retrieved as part of your vulnerability report as soon as it is no longer required.
- Perform coordinated disclosure by not publicly disclosing the vulnerability before the expiration of a mutually agreed timeline.
Report a Vulnerability Form
Please use the form provided below to share as many details as possible. This will enable our engineering teams to quickly validate and address the issue. Your submission will be directly sent to the PI Product Security Team, initiating the necessary process.
Before reporting a vulnerability, we recommend familiarizing yourself with the PI Coordinated Vulnerability Disclosure Policy (>> Coordinated Vulnerability Disclosure Policy).
For technical support, please refer to the respective product page.