Bepto Pneumatic
Vulnerability Disclosure Policy
This policy explains how to report a suspected security vulnerability affecting the Bepto Pneumatic website. Bepto Pneumatic is the pneumatic product line of Bepto Industrial.
How to Report a Vulnerability
Email security reports to security@bepto.com. Use a clear subject line such as “Security report: rodlesspneumatic.com” and include the affected URL or feature, potential impact, reproduction steps, request and response details, a minimal proof of concept, required conditions, and your preferred contact details.
Do not include unnecessary personal data, customer information, credentials, or confidential material in the initial report.
Scope
This policy applies to rodlesspneumatic.com, including first-party pages, public Worker routes, and website forms operated by Bepto Pneumatic. Contact us before testing if you are uncertain whether a system is in scope.
Third-party platforms, infrastructure, applications, and services are outside this policy unless explicitly identified as operated by Bepto Pneumatic. Report third-party vulnerabilities to the relevant provider.
Good-Faith Research Rules
Use only accounts, records, and data that you own or have permission to access. Use the minimum testing needed to confirm an issue; do not access, copy, change, retain, or delete data beyond that minimum. Stop and notify us if you encounter personal data, credentials, confidential information, or another person’s records. Avoid disruption, excessive automated requests, resource exhaustion, and effects on customers, availability, or production data. Give us a reasonable opportunity to investigate before public disclosure, comply with applicable law, and do not use a vulnerability for extortion or payment demands.
Prohibited Testing
This policy does not authorize denial-of-service, traffic flooding, destructive testing, social engineering, phishing, spam, credential stuffing, physical intrusion, malware, persistence, production-data modification, high-volume scanning that degrades service or ignores safety controls, attacks against people or service providers, or testing of third-party systems and Cloudflare infrastructure that Bepto Pneumatic does not operate.
Reports That Usually Do Not Qualify
We welcome evidence of real security impact. Reports limited to scanner output, software version banners, missing optional headers, self-XSS, content or SEO issues, clickjacking on pages without sensitive actions, or rate-limit observations without a demonstrated security consequence may be closed without remediation.
Our Response
We will make a reasonable effort to acknowledge a complete report within five business days, provide an initial assessment or request more details within ten business days, and share material progress updates when appropriate. These are good-faith targets, not contractual service levels; remediation time depends on severity, complexity, affected services, and provider coordination.
Coordinated Disclosure
Do not publicly disclose a suspected vulnerability, proof of concept, or affected data until we confirm remediation or agree on a disclosure date. We will work in good faith toward a reasonable timeline based on severity and complexity.
Safe Harbor
Bepto Pneumatic does not intend to initiate legal action against security research conducted in good faith, within this policy, and in a manner designed to avoid harm. Contact us before proceeding if a planned test may be unclear. This statement does not authorize violations of law or bind third parties.
Recognition and Rewards
This policy is not a bug bounty program and does not promise payment, gifts, or public recognition. Any acknowledgment or reward is entirely discretionary and must be agreed separately in writing.
Contact
Security reports: security@bepto.com
Product, quotation, and ordinary website questions: Pneumatic@bepto.com