Security

Vulnerability Disclosure Policy

If you have found a security issue in a PAVO Fitness app, device or API, we want to hear about it. This page tells you what is in scope, how to reach us, and what happens after you send a report.

Version 1.0 Last updated 2026-09-07

Report a vulnerability security.txt

01Introduction

PAVO Fitness builds connected strength-training hardware and the mobile applications that drive it. Our products handle account data, device provisioning, firmware delivery and streamed workout content, so we treat security as part of the product, not as an afterthought.

We welcome reports from independent security researchers. If you have found a vulnerability in a PAVO Fitness product or service, we want to hear about it, and we will work with you to understand, validate and fix it.

Thank you for taking the time to look. Reports from the research community have a direct effect on the safety of our users.

02In scope

The following are covered by this policy:

  • PAVO Fitness for iOS — released builds distributed through the App Store (current release 0.6.7)
  • PAVO Fitness for Android — released builds distributed through Google Play (current release 0.0.1+5, version code 6)
  • Device firmware and the Bluetooth Low Energy protocol used between the apps and PAVO hardware, including the secure-channel handshake, device activation and over-the-air firmware update paths
  • PAVO production APIs across all served regions (Americas, EMEA, APAC)
  • pavofitness.com and the subdomains explicitly listed on this page

03Out of scope

The following are not covered. Reports limited to these categories will be closed without a detailed assessment.

  • The Shopify platform itself. www.pavofitness.com runs on Shopify. Vulnerabilities in the Shopify platform, its themes framework or its infrastructure must be reported to Shopify through their own program.
  • Third-party services we consume, including AWS Cognito, AWS Amplify and other managed platform components. Report those to the service owner.
  • Non-production environments — development and staging endpoints, TestFlight builds, internal beta channels and any unreleased build.
  • Denial of service, stress testing, resource exhaustion or any technique whose effect is to degrade availability.
  • Social engineering and phishing targeting our staff, our users or our partners.
  • Physical attacks against our offices, our facilities or any data centre.
  • Unvalidated automated scanner output. Raw tool output without manual verification and a demonstrated security impact is not a report.
  • Issues that require a jailbroken or rooted device to reproduce, unless agreed with us in advance.
  • Missing security headers, weak TLS suite preferences, SPF/DKIM/DMARC nits and similar best-practice findings with no demonstrated impact.
  • Self-XSS, clickjacking on pages with no sensitive action, and vulnerabilities that require a fully compromised device or a physically present attacker with an unlocked phone.

04Bug bounty

We do not currently operate a paid bug bounty programme. We do not offer monetary rewards, swag or bounty-style payouts for reports submitted under this policy.

We do commit to responding, to keeping you informed, and to crediting your work in our internal remediation record.

We do not maintain a public acknowledgements page. If you would like your finding referenced in a published advisory, tell us in your report and we will discuss the wording with you before anything is made public.

06What to include

A good report lets us reproduce the issue without a round trip. Please include:

  1. Affected product and version — for example PAVO Fitness iOS 0.6.7, the firmware version, or the API region and endpoint.
  2. Vulnerability type — what class of issue this is.
  3. Reproduction steps — precise, ordered, and complete enough for a third party to follow.
  4. Impact — what an attacker gains, and under what preconditions.
  5. Evidence — request and response captures, BLE traces, logs, screenshots or a short video.
  6. Proof-of-concept code, if you have it.
  7. Environment — device model, OS version, network conditions, and any tooling or proxy configuration required.
  8. Your preference on attribution and whether you intend to publish.

Please do not include third-party personal data in your report. If your testing incidentally exposed user data, stop, tell us immediately, and do not retain a copy.

07Our process

Response targets from the date we receive your report.
StageTarget
Acknowledge receiptWithin 3 business days
Initial validation and severity assessmentWithin 10 business days
Progress updates during remediationAt regular intervals until closed
Coordinated public disclosureWhen a fix is available, if publication is appropriate

High-severity issues are escalated ahead of the queue.

Remediation timelines depend on the affected component. A server-side fix can ship quickly; a mobile release must clear App Store or Google Play review; a firmware fix must be staged through over-the-air update and reach devices in the field. We will tell you which of these applies to your report.

Disclosure window

We ask that you give us 90 days from your first report before disclosing publicly. If we need longer we will explain why and agree a revised date with you. If we fix the issue sooner, we are happy to coordinate an earlier publication.

Where a fix is shipped and publication serves our users, we publish a Security Advisory.

08Rules of engagement

While researching, please:

  • Only test against accounts and devices you own or are explicitly authorised to test.
  • Stop as soon as you have confirmed a vulnerability. Do not pivot, do not escalate further than needed to demonstrate impact, and do not attempt to access data belonging to anyone else.
  • Do not modify, exfiltrate, destroy or retain data that is not yours.
  • Do not degrade the availability or integrity of our services.
  • Do not use findings for extortion, and do not condition disclosure on payment.
  • Give us a reasonable opportunity to fix the issue before going public.
  • Comply with applicable law.

Testing that violates these rules is not authorised under this policy.

09Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will treat your activity as authorised. We will not initiate or recommend legal action against you in connection with that research, and if a third party brings action against you for work conducted within the scope of this policy, we will make it known that your activity was authorised.

If you are unsure whether a particular test is within scope, ask us first at develop@pavofitness.com before you proceed.

This section does not waive any right or protection of any third party, and it does not authorise activity that is unlawful in your jurisdiction.

Status: undergoing final legal review. The commitment above reflects our intent; the binding wording will be confirmed in writing.

11Changes to this policy

This policy may be updated. The version and last-updated date at the top of the page always reflect the current text.