Current status
PalmX has not supplied a verified, monitored security-disclosure mailbox for this release. For that reason, no security email address is published here and the security.txt endpoint fails closed until an owner configures and tests a real channel.
When a report is welcome
When the channel is activated, reports should concern a real security weakness in PalmX-controlled public systems and include enough detail to reproduce safely. A client system, third-party service, or engagement target is out of scope unless its owner has given written authorization.
Safe research boundaries
- Avoid privacy violations, data exfiltration, persistence, denial of service, destructive actions, social engineering, and physical access.
- Stop testing when you encounter personal, confidential, or production data and report the minimum necessary evidence.
- Do not publicly disclose a weakness while PalmX or the affected owner is investigating and coordinating remediation.
- Do not demand payment, threaten disclosure, or submit duplicate or intentionally misleading reports.
Review process
The final program will define acknowledgement, triage, severity, communication, remediation, disclosure, and researcher-credit rules only after the mailbox owner, response target, disclosure authority, and client coordination path are approved.
This is an operational draft for review and approval. Do not use it to determine rights or obligations until it is approved by the authorized owner.