Last updated: September 4, 2026
Report a security issue
Submit potential vulnerabilities and security incidents only through the Planobot contact form, selecting Security issue. The automated receipt confirms submission but is not a human acknowledgment. Planobot aims to provide a human acknowledgment within five business days. Confirmed urgent impact immediately enters the internal incident process.
What to include
Provide a concise description of the issue, affected Planobot URL or desktop version, approximate UTC time, potential impact, and the minimum reproducible steps. Minimize sensitive data. Do not include passwords, session cookies, access tokens, private keys, unnecessary personal data, complete message bodies, or live exploit payloads beyond what is needed to explain the issue.
Safe research expectations
Test only with accounts and data you own or are explicitly authorized to use. Do not access, retain, modify, or delete another user's data; establish persistence; degrade the service; perform denial-of-service, social-engineering, or physical attacks; or exfiltrate data. Stop testing and report immediately if you encounter another user's data or a risk of harm.
Response and remediation
Planobot reviews reports during U.S. business days. The acknowledgment target is not a remediation or resolution deadline. Planobot may request clarification, verification, or coordination and cannot promise a particular fix, timeline, or outcome. Ordinary product bugs should use the Support Policy.
Confidentiality and coordinated disclosure
Keep the report and vulnerability confidential until Planobot confirms a coordinated disclosure date or that the issue is resolved. Planobot does not promise a bug bounty, payment, credit, or other reward. This policy does not authorize conduct that violates law, third-party terms, or other users' rights.
The machine-readable reporting record is available at /.well-known/security.txt.