Overview
This Security Policy and Vulnerability Disclosure Policy ("Policy") applies to the PageLantern service operated by PageLantern LLC, a Texas limited liability company, doing business as PageLantern ("PageLantern," "we," "us," and "our"). We operate a coordinated vulnerability disclosure process and do not run a paid bug-bounty program. We will not pursue or support legal action against researchers for good-faith security research conducted in accordance with this Policy, as described in the Safe Harbor section below. This Policy works alongside, and does not replace, our Terms of Service, Acceptable Use Policy, and Privacy Notice; where this Policy authorizes good-faith testing, it does so only to the limited extent described here.
1. Introduction and Purpose
Keeping the PageLantern service and its users safe is a priority for us, and independent security researchers play an important part in that. This Policy gives security researchers clear guidelines for conducting good-faith vulnerability discovery and a clear way to report what they find. It also tells you what you can expect from us in return.
By participating in security research or submitting a report under this Policy, you acknowledge that you have read and agree to it. If any part of this Policy conflicts with your local law or with another agreement you have with us, do not take any action that would be unlawful, and contact us first at security@pagelantern.com if you are unsure.
2. Scope
This Policy authorizes good-faith security testing of the systems we operate that directly serve the PageLantern product, namely:
- The PageLantern web application, customer portal, and dashboards at pagelantern.com and its subdomains.
- The PageLantern monitoring API and API endpoints served from those domains.
- Other infrastructure that PageLantern itself operates and that directly serves the systems above.
3. Out of Scope
The following activities and targets are out of scope and are not authorized by this Policy. Conducting them is not protected by the Safe Harbor below:
- Denial-of-service (DoS or DDoS) attacks, and any volumetric, load, stress, or resource-exhaustion testing.
- Social engineering, phishing, or pretexting of our staff, contractors, users, or vendors, and any physical attacks on people or property.
- Attacks against, or testing of, third-party services, sub-processors, or infrastructure we do not own or operate (including services a customer has configured PageLantern to reach).
- Automated scanning or fuzzing that degrades, disrupts, or materially loads the service.
- Spam, mass account creation, or content injection that affects other users.
- Any testing that accesses, modifies, deletes, exfiltrates, or retains data belonging to other users or organizations. Use only your own test accounts and test data.
The following are typically not eligible as vulnerabilities on their own and may be closed without action: missing security headers or cookie flags without a demonstrated exploit; reports generated solely by automated tools without a working proof of concept; theoretical issues, version-disclosure or banner-grabbing findings, and missing best practices without a concrete, demonstrable security impact; rate-limiting reports on already-known endpoints; and self-inflicted or socially engineered issues affecting only the researcher's own session.
4. Researcher Obligations (Rules of Engagement)
To qualify for the Safe Harbor described below, your testing must be conducted in good faith and you must:
- Make a good-faith effort to avoid privacy violations, degradation of the service, and destruction or modification of data.
- Use only your own accounts and test data, and never access, alter, or interact with data that belongs to anyone else.
- Stop testing and notify us immediately at security@pagelantern.com if you encounter any personal, confidential, or other sensitive data, and not access, copy, store, share, or retain that data beyond the minimum reasonably necessary to document the issue, then securely delete it.
- Limit any proof of concept to the minimum interaction needed to confirm the vulnerability, and not pivot, escalate, or maintain access beyond that point.
- Give us a reasonable opportunity to investigate and remediate before disclosing any finding publicly, and coordinate the timing of any public disclosure with us.
- Comply with all applicable laws, and not engage in extortion, threats, or any demand for payment in exchange for disclosing or withholding a vulnerability.
5. How to Report
Send vulnerability reports to security@pagelantern.com. Our machine-readable contact details are also published at https://pagelantern.com/.well-known/security.txt.
To help us triage quickly, please include a clear description of the issue, the affected URL, endpoint, or component, step-by-step reproduction instructions, a proof of concept where possible, and your assessment of the impact. We accept reports in English.
You may report anonymously. We do not require your identity or any personal information in order to receive, investigate, and act on a report, although providing a way to contact you helps us coordinate and credit your work.
6. Safe Harbor
When you conduct security research and vulnerability disclosure in good-faith compliance with this Policy, we will: (1) consider that research to be authorized under the Computer Fraud and Abuse Act and equivalent state and foreign anti-hacking laws (including, where applicable, the UK Computer Misuse Act); (2) not pursue or support any civil or criminal action against you, and waive any claim under the Digital Millennium Copyright Act Section 1201 and equivalent anti-circumvention laws, for activities conducted in accordance with this Policy; and (3) waive any restriction in our Terms of Service or Acceptable Use Policy that would otherwise prohibit such research, but only to the limited extent necessary to permit the good-faith testing described in this Policy.
If a third party initiates legal action against you for activities that were conducted in accordance with this Policy, we will take steps to make it known that your actions were authorized under this Policy.
This Safe Harbor applies only to legal claims under our control. It does not bind any third party, and it does not authorize any activity that is unlawful independent of this Policy. If at any time you are unsure whether your intended conduct is consistent with this Policy, contact us at security@pagelantern.com before proceeding and we will clarify. We may, at our discretion, determine in good faith that particular conduct was not a good-faith effort to follow this Policy, and decline to extend the Safe Harbor to that conduct.
7. Good-Faith Standard
"Good faith" means security research that is carried out with the intent to follow this Policy, without malicious intent, and without intent to harm us, our users, or the public. We assess good faith based on your conduct, your statements, and the results of your testing, rather than on stated intentions alone.
8. No Bounty or Compensation
PageLantern does not operate a paid bug-bounty program. We do not offer monetary rewards, swag, or other compensation for vulnerability reports, and submitting a report does not create any expectation of payment or any other obligation on our part.
With your permission, and after a fix has been released, we are happy to acknowledge your contribution publicly. We will not publicly identify or credit you without your consent.
9. Coordinated Disclosure Timeline
We follow a coordinated disclosure model. We aim to acknowledge your report within a few business days and to keep you reasonably informed of our remediation progress. We ask that you keep your report confidential until we have had a reasonable opportunity to remediate, and that you coordinate the timing and content of any public disclosure with us.
As a general guideline, we target remediation of confirmed, significant issues within 90 days, and we will discuss timelines with you for complex cases. These are goals, not guarantees or service-level commitments, and they may vary with the severity and complexity of the issue.
10. Reservation of Rights
We reserve the right to change, suspend, or terminate this Policy at any time; to determine, in good faith, whether a report and the conduct that produced it fall within this Policy; and to decline the Safe Harbor for conduct that falls outside it.
Participation under this Policy does not grant you any license to our intellectual property beyond what is strictly necessary to perform authorized testing, and it does not create any employment, agency, partnership, joint venture, or other contractual relationship between you and PageLantern.
11. Legal Disclaimers
This Policy does not waive any rights of third parties, and it does not affect your obligations under any law or agreement that is not within our control. Nothing in this Policy authorizes any activity that is prohibited by law independent of this Policy.
Any reference in this Policy to a government enforcement posture — for example, the U.S. Department of Justice's stated policy of declining to charge good-faith security research under the Computer Fraud and Abuse Act — is provided for context only. Such guidance is internal prosecutorial policy, is not a statutory safe harbor, creates no legal defense that you can assert, and does not affect civil liability or state computer-crime laws.
This Policy is not legal advice. Governing law, venue, dispute resolution, warranty disclaimers, and limitations of liability are set out in our Terms of Service, which continue to apply except to the limited extent the Safe Harbor expressly modifies them for good-faith research.
12. Contact
Report security issues using the details below. Please include enough information for us to reproduce and assess the issue, and avoid sharing secrets or other people's data unless it is necessary and safe to do so.
- Security reports
- security@pagelantern.com
- Machine-readable contact (RFC 9116)
- pagelantern.com/.well-known/security.txt
- Security overview
- pagelantern.com/security
- Terms of Service
- pagelantern.com/terms
- Acceptable Use Policy
- pagelantern.com/acceptable-use
Postal address: PO Box 340351, Lakeway, TX 78734. Security correspondence is answered fastest at security@pagelantern.com.
Important Note
This Security Policy and Vulnerability Disclosure Policy is provided to make good-faith security research safe and predictable; it is not legal advice and does not create rights or obligations beyond those it expressly states. The Safe Harbor applies only to legal claims within our control and does not bind third parties or authorize unlawful activity. Scope domains and the governing-law reference in this Policy are reviewed alongside our Terms of Service, Acceptable Use Policy, and Privacy Notice.
