Responsible Disclosure Policy

Pyramid Network Services, LLC

Pyramid Network Services, LLC (PNS) values the work of security researchers and members of the public who help keep our systems and our customers' information secure. If you believe you have found a security vulnerability in a PNS system, website or service, we want to hear from you.

How to report. Email security@pyramidns.com. Include the affected system or URL, a description of the issue, steps to reproduce, and any supporting material. If you need to send sensitive details, ask us for an encrypted channel first. You may report anonymously.

What we ask of you. Act in good faith: do not access, modify or destroy data that isn't yours; do not degrade our services; do not use social engineering, phishing or physical attacks against PNS employees, facilities or customers; stop testing and report immediately if you encounter personal or customer data; and give us a reasonable time to remediate before any public disclosure.

What you can expect from us. We will acknowledge your report within three business days, keep you informed of our progress, work with you to understand and validate the issue, and remediate confirmed vulnerabilities based on severity. We will not pursue legal action against researchers who follow this policy, and we will not share your identity without your permission. PNS does not currently operate a paid bounty program.

Scope. Systems and services operated by PNS, including pyramidns.com. Systems operated by our customers or by third-party providers on their own infrastructure are out of scope; please report those to the operator directly.

Contact. security@pyramidns.com · Pyramid Network Services, LLC, 5845 Widewaters Parkway, Suite 100, East Syracuse, NY 13057