Loading

Vulnerability Disclosure & Information Handling

What we handle

Our engagements are centered on responsible vulnerability discovery, remediation support, and security assurance. We work as an internal security capability with clearly defined scopes, review controls, and evidence-handling standards. We do not outsource core testing functions or disclosure decisions to informal third parties.

Public web applications, services, APIs, and internet-facing assets under Palota ownership
Authentication, authorization, session control, and configuration weaknesses affecting live systems
Client assessments performed under formal scope, NDA, and approved testing boundaries

Confidentiality and client data handling

When clients engage Palota for VAPT or security assessments, their environments, findings, and evidence are treated as confidential. Information is shared only with authorized project stakeholders, and sensitive evidence is kept minimal, protected, and reviewed before disclosure.

Data minimization: only the information needed for validation, reporting, and remediation is collected and retained.

Access control: findings are handled by authorized security personnel under least-privilege access, with no unnecessary sharing across teams.

Public disclosure rules: client-sensitive findings are only disclosed publicly when the client approves the release or the issue is already in an approved remediation and communication schedule.

Out of scope

  • Social engineering, phishing, or impersonation attempts against employees, vendors, or partners
  • Physical security testing unrelated to a Palota-owned or client-authorized asset
  • Denial-of-service testing that intentionally impacts service availability or customer operations
  • Issues affecting third-party platforms, suppliers, or services outside the agreed engagement scope
  • Publicly known findings that have already been reported without an active remediation window or client authorization