Report a vulnerability | Pruff
Menu
Pruff FinancingRun credit end to end. Pruff FundsConnect capital to the operations.
About us Careers
Blog
Language
Sign in Request a demo
Back to home
Security

Report a vulnerability

If you found a security flaw in the platform, this is the channel. We review it with the same procedure we use for any security incident.

Pruff handles sensitive information from lenders, funds and their clients. If you found a flaw that exposes data, grants access to something it should not, or degrades the service, we want to know before anyone else does.

This form goes straight to the security team. You do not need a Pruff account or to be a client to use it.

{{ errVEmail }}
{{ errVDetalle }}
We could not send the report
Write to us directly at support@pruff.com with the same detail.
{{ vHint }}
We received your report

We will acknowledge receipt within one business day at the email you provided.

What we do with your report

We acknowledge receipt within one business day at the email you provided.
We assess it with our security incident management procedure: it is classified by priority and assigned an owner.
We fix it and verify. Where applicable, the fix goes through the production change process and is tested again.
We tell you how it closed. If the finding was valid, we tell you what was done.

What we ask of you

Nothing legalistic, just what is reasonable for this to work:

Do not access, copy or modify data that is not yours. If you stumbled onto third-party data, stop and tell us.
Do not degrade the service: no denial-of-service or load testing against production.
Give the team time before publishing. Let us coordinate disclosure.
A report with steps to reproduce is worth ten times a lone screenshot.

What is out of scope

This channel is for platform security flaws. If it is an issue with your day-to-day operation, a data error or a usage question, your usual support channel will be much faster.