Last updated: March 2025
This policy applies to all vulnerabilities identified by external researchers, security professionals, or any third-party entities concerning Pipe17’s systems, software, applications, or services.
To define clear guidelines and procedures for responsibly reporting security vulnerabilities to Pipe17, ensuring timely acknowledgment, assessment, and remediation of vulnerabilities, thereby maintaining the security and integrity of Pipe17 services.
Upon verification, vulnerabilities will be categorized based on severity, with remediation targets as follows:
Severity Level | Remediation Timeline |
| Critical | Within 7 days |
| High | Within 14 days |
| Medium | Within 30 days |
| Low | Within 60 days |
Any exceptions to the stated timelines or procedures must be explicitly approved by the Pipe17 CTO or VP of Engineering.
This policy will be reviewed and updated annually, or more frequently if necessary, to ensure alignment with evolving security practices and standards.