security
Last Updated: June 1, 2026
Coordinated Vulnerability Disclosure Policy
At PAQR, we consider the security and privacy of our packaging data platform a top priority. We appreciate the work of ethical security researchers who help us maintain a secure environment for all our enterprise users. If you believe you have discovered a vulnerability, we welcome your report according to the guidelines below.
How to Report
Please submit your findings directly to our security engineering team at security(at)paqr.com.
To help us triage your report quickly, please include:
- A clear description of the potential vulnerability.
- Step-by-step instructions (or a proof-of-concept script) to reproduce the issue.
- The potential impact if exploited.
Rules of Engagement (Safe Harbor)
To protect our customers and infrastructure, we ask that you adhere to the following rules:
- No Data Disruption: Do not attempt to access, modify, or delete data belonging to other users or tenants.
- No Service Degradation: Avoid any actions that degrade platform performance, including volumetric testing or Denial of Service (DoS/DDoS) simulations.
- Responsible Disclosure: Give our engineering team a reasonable window of time to investigate and remediate the issue before publicizing any details.
Out of Scope
The following testing methods are strictly prohibited and do not qualify for our program:
- Social engineering, phishing, or physical security testing of our employees or offices.
- Automated scanner reports without validation or a functional proof-of-concept.
- Spamming or brute-force testing of user accounts.
Thank you for helping us keep the packaging value chain secure!