Security

Vulnerability Disclosure Policy

If you have found a security issue in a PAVO Fitness app, device or API, we want to hear about it. This page tells you what is in scope, how to reach us, and what happens after you send a report.

Version 1.0 Last updated 2026-09-07

Report a vulnerability security.txt

01Introduction

PAVO Fitness builds connected strength-training hardware and the mobile applications that drive it. Our products handle account data, device provisioning, firmware delivery and streamed workout content, so we treat security as part of the product, not as an afterthought.

We welcome reports from independent security researchers. If you have found a vulnerability in a PAVO Fitness product or service, we want to hear about it, and we will work with you to understand, validate and fix it.

Thank you for taking the time to look. Reports from the research community have a direct effect on the safety of our users.

02In scope

The following are covered by this policy:

  • PAVO Fitness for iOS — released builds distributed through the App Store (current release 0.6.7)
  • PAVO Fitness for Android — released builds distributed through Google Play (current release 0.0.1+5, version code 6)
  • Device firmware and the Bluetooth Low Energy protocol used between the apps and PAVO hardware, including the secure-channel handshake, device activation and over-the-air firmware update paths
  • PAVO production APIs across all served regions (Americas, EMEA, APAC)
  • pavofitness.com and the subdomains explicitly listed on this page

03Out of scope

The following are not covered. Reports limited to these categories will be closed without a detailed assessment.

  • The Shopify platform itself. www.pavofitness.com runs on Shopify. Vulnerabilities in the Shopify platform, its themes framework or its infrastructure must be reported to Shopify through their own program.
  • Third-party services we consume, including AWS Cognito, AWS Amplify and other managed platform components. Report those to the service owner.
  • Non-production environments — development and staging endpoints, TestFlight builds, internal beta channels and any unreleased build.
  • Denial of service, stress testing, resource exhaustion or any technique whose effect is to degrade availability.
  • Social engineering and phishing targeting our staff, our users or our partners.
  • Physical attacks against our offices, our facilities or any data centre.
  • Unvalidated automated scanner output. Raw tool output without manual verification and a demonstrated security impact is not a report.
  • Issues that require a jailbroken or rooted device to reproduce, unless agreed with us in advance.
  • Missing security headers, weak TLS suite preferences, SPF/DKIM/DMARC nits and similar best-practice findings with no demonstrated impact.
  • Self-XSS, clickjacking on pages with no sensitive action, and vulnerabilities that require a fully compromised device or a physically present attacker with an unlocked phone.

04Rewards

We offer a reward for reports that identify a genuine, previously unknown vulnerability in something listed in In scope.

Depending on the severity and quality of the report, a reward may be a cash payment of up to USD 1,000, or PAVO Fitness merchandise.

Rewards are discretionary. We decide the amount and the form, and we will tell you what we have decided when we confirm the issue. A clear, reproducible report with a demonstrated impact is worth more to us than a raw finding, and we weigh that.

A reward requires all of the following

  • The issue is in scope and is not excluded by Out of scope.
  • You are the first person to report it to us.
  • The issue was previously unknown to us.
  • You followed the rules of engagement.
  • Paying you is lawful in your jurisdiction and ours, and you are not on a sanctions list. We cannot pay where the law forbids it.

We do not pay for duplicates, for issues we already knew about, for anything listed as out of scope, or for reports that turn out not to be exploitable.

Payment method and any tax or reporting obligations are settled with you directly after the issue is confirmed. Any tax owed on a reward is yours to handle.

We do commit to responding, to keeping you informed, and to crediting your work in our internal remediation record.

We do not maintain a public acknowledgements page. If you would like your finding referenced in a published advisory, tell us in your report and we will discuss the wording with you before anything is made public.

05How to report

Send your report to:

develop@pavofitness.com

For anything containing exploit detail, credentials, user data or an unfixed vulnerability, please encrypt it with our PGP key.

Email

develop@pavofitness.com

English and Simplified Chinese

PGP key

security.pavofitness.com/pgp-key.txt

Fingerprint
55E6 F7CE A1D2 369C CDD6 63F1 B60F F645 E7B8 B98B

security.txt

/.well-known/security.txt

RFC 9116 machine-readable contact

06What to include

A good report lets us reproduce the issue without a round trip. Please include:

  1. Affected product and version — for example PAVO Fitness iOS 0.6.7, the firmware version, or the API region and endpoint.
  2. Vulnerability type — what class of issue this is.
  3. Reproduction steps — precise, ordered, and complete enough for a third party to follow.
  4. Impact — what an attacker gains, and under what preconditions.
  5. Evidence — request and response captures, BLE traces, logs, screenshots or a short video.
  6. Proof-of-concept code, if you have it.
  7. Environment — device model, OS version, network conditions, and any tooling or proxy configuration required.
  8. Your preference on attribution and whether you intend to publish.

Please do not include third-party personal data in your report. If your testing incidentally exposed user data, stop, tell us immediately, and do not retain a copy.

07Our process

Response targets from the date we receive your report.
StageTarget
Acknowledge receiptWithin 3 business days
Initial validation and severity assessmentWithin 10 business days
Progress updates during remediationAt regular intervals until closed
Coordinated public disclosureWhen a fix is available, if publication is appropriate

High-severity issues are escalated ahead of the queue.

Remediation timelines depend on the affected component. A server-side fix can ship quickly; a mobile release must clear App Store or Google Play review; a firmware fix must be staged through over-the-air update and reach devices in the field. We will tell you which of these applies to your report.

Disclosure window

We ask that you give us 90 days from your first report before disclosing publicly. If we need longer we will explain why and agree a revised date with you. If we fix the issue sooner, we are happy to coordinate an earlier publication.

Where a fix is shipped and publication serves our users, we publish a Security Advisory.

08Rules of engagement

While researching, please:

  • Only test against accounts and devices you own or are explicitly authorised to test.
  • Stop as soon as you have confirmed a vulnerability. Do not pivot, do not escalate further than needed to demonstrate impact, and do not attempt to access data belonging to anyone else.
  • Do not modify, exfiltrate, destroy or retain data that is not yours.
  • Do not degrade the availability or integrity of our services.
  • Do not use findings for extortion. Asking about a reward is fine; withholding details, threatening publication or threatening to sell the finding in order to extract payment is not, and forfeits any reward.
  • Give us a reasonable opportunity to fix the issue before going public.
  • Comply with applicable law.

Testing that violates these rules is not authorised under this policy.

09Safe harbor

To encourage security research and responsible disclosure, PAVO Fitness will not take legal action against security researchers who make a good-faith effort to comply with this policy and who report security vulnerabilities as it requires.

Please understand that if your research involves the networks, systems, information, applications, products or services of a third party — that is, anyone other than us — we cannot bind that third party. They may take legal action of their own or notify law enforcement. We cannot and do not authorise security research on behalf of any other entity, and we cannot defend, indemnify or otherwise protect you against a third-party claim arising from your own conduct.

As always, we expect you to comply with every law that applies to you, and not to disrupt or compromise any data beyond what this policy permits.

Before engaging in conduct that may be inconsistent with this policy, or that this policy does not cover, please contact us at develop@pavofitness.com. We reserve sole discretion to determine whether you made a good-faith effort to comply with this policy and to report as it requires — and contacting us first, before you act, weighs heavily in that determination.

When in doubt, ask us first.

Status: undergoing final legal review. The commitment above reflects our intent; the binding wording will be confirmed in writing.

11Changes to this policy

This policy may be updated. The version and last-updated date at the top of the page always reflect the current text.