Legal
Security Policy
HoneyPeer, LLC takes the security of PearDock seriously. This policy describes how to report vulnerabilities responsibly.
Last updated: July 11, 2026
1. Scope
In scope:
- PearDock server and client software as published by HoneyPeer;
- Official installers and websites (peardock.boats, install.peardock.boats);
- Cryptographic handling of peer identity and RPC transport where implemented by PearDock.
Generally out of scope:
- Issues solely in third-party dependencies without a demonstrated impact on PearDock (report upstream when appropriate);
- Social engineering of HoneyPeer staff;
- Denial-of-service volume testing against production Sites without prior coordination;
- Findings that require physical access or already-compromised admin credentials on the target host.
2. How to report
Email legal@honeypeer.com with:
- description of the issue and potential impact;
- steps to reproduce or proof-of-concept (non-destructive);
- affected versions / commit / platform if known;
- your contact details and any preferred credit name.
Please use English if possible. Do not include sensitive personal data of third parties.
3. Safe harbor
If you make a good-faith effort to follow this policy, avoid privacy violations, service disruption, and data destruction, and do not exploit the issue beyond what is necessary to demonstrate it, HoneyPeer will not pursue legal action against you for that research under laws applicable to unauthorized access, to the extent we can bind ourselves. This does not authorize attacks on third-party systems or users’ self-hosted instances without their permission.
4. Our process
- We will acknowledge receipt when practicable;
- We will investigate and may request more detail;
- We aim to remediate or mitigate high-severity issues in a reasonable timeframe;
- We may publicly credit reporters who wish to be credited after a fix is available.
We do not guarantee a bug bounty payment unless a separate program is announced.
5. For operators
Production hardening guidance is available in the product docs:
Security & threat model and
Operator guide.
Keep PearDock and Docker updated; protect SERVER_SEED and peer allowlists.
6. Contact
Contact: legal@honeypeer.com
HoneyPeer, LLC · DeKalb County, Georgia, USA