Security

Security & Responsible Disclosure

Effective January 5, 2026

Our Approach

  • Industry-standard practices for authentication, encryption-in-transit (HTTPS), and key management.
  • Principle of least privilege for internal access; audit logging for sensitive actions where applicable.
  • Regular dependency updates and monitoring for known vulnerabilities.

Responsible Disclosure

If you discover a potential security issue, please contact us at security@planewx.com with enough detail to reproduce. Do not publicly disclose before we confirm and address the issue.

  • Do not access, modify, or exfiltrate data that is not yours. Use test accounts only.
  • Do not disrupt services (no DDoS, spam, or load tests).
  • No social engineering, phishing, or physical intrusion.
  • No automated scanning of production beyond what is necessary to validate a specific finding.

We currently do not offer a bug bounty. We appreciate responsible reports and will acknowledge valid findings.

Incident Response

We investigate reported issues promptly. If user data is impacted, we will notify affected users as required by law.

Contact

Security reports: security@planewx.com. Other questions: support@planewx.com.