Vulnerability Disclosure


15 September 2026

Classification: Public

Perlina TV takes the security of our products seriously. If you believe you've found a security vulnerability, or have evidence that a vulnerability is being actively exploited, we want to hear from you.

This page is an interim disclosure page. A fuller coordinated vulnerability disclosure policy, including formal safe-harbour terms, is planned ahead of December 2027.

How to report

Contact: [email protected]

PGP key: Download

Fingerprint: BC48 2681 5FFE DF00 FB18  894F 1A60 E6E2 6012 D938

Languages: English

Reporting sensitive vulnerabilities

If your report includes details of an unpatched or actively exploited vulnerability, please encrypt it using our PGP key before emailing it to us:

  1. Download our public key from the link above, or fetch it from keys.openpgp.org by searching the fingerprint.
  2. Verify the fingerprint matches the one published on this page before trusting the key — don't rely solely on a key found elsewhere.
  3. Encrypt your report to that key (e.g., gpg --encrypt --armor --recipient [email protected] report.txt, or using your mail client's built-in OpenPGP support).
  4. Send the encrypted message to [email protected].

Encryption is optional for general or low-sensitivity reports, but strongly recommended for anything involving an unpatched vulnerability or evidence of active exploitation.

Encrypting vs. signing: Encrypting your report to our public key ensures only we can read it. If you'd also like to prove the report came from you (and let us verify it hasn't been tampered with), you can additionally sign it with your own PGP key before encrypting (gpg --sign --encrypt --armor --recipient [email protected] --local-user your-key-id report.txt). Signing is optional and only meaningful if you have your own key pair — it authenticates the sender, it does not replace encryption.

Please include as much of the following as you can:

  • Product and version affected
  • Description of the vulnerability
  • Steps to reproduce, or a proof of concept, if available
  • Any evidence suggesting the vulnerability is being actively exploited (e.g., logs, indicators of compromise)
  • Your contact details, if you'd like a response

What to expect

  • Acknowledgement of your report: Within 48 hours
  • Initial review: Within 5–10 business days
  • Follow-up or resolution update: As the assessment progresses

We review every report in good faith. Depending on the outcome of our assessment, a confirmed vulnerability may trigger further internal processes, including regulatory reporting where required by law.

Good-faith research

Perlina TV does not currently offer a formal safe-harbour commitment or bug bounty program. We ask that researchers:

  • Avoid accessing, modifying, or deleting data that isn't their own
  • Avoid degrading the availability of our services
  • Give us a reasonable opportunity to investigate and address a report before any public disclosure
  • Not use automated scanning that could impact production systems without prior contact

Scope

This channel is for security vulnerabilities in Perlina TV's products with digital elements. For other issues (general support, billing, feature requests), please use [email protected].