Pioneer Vulnerability Disclosure Policy
Last updated: August 25, 2026
Mycorrxyz Inc. dba Pioneer welcomes good-faith security research. If you believe you've found a vulnerability in Pioneer, we want to hear about it.
Scope
- pioneerclimate.com and the Pioneer application at usepioneer.ai
- Pioneer-operated APIs
Out of scope: third-party services we use (report to them directly), social engineering, physical attacks, denial-of-service testing, spam/volume-based findings, and clickjacking on pages without sensitive actions.
How to report
Email privacy@pioneerclimate.com with:
- a description of the issue and its impact;
- steps to reproduce (proof-of-concept appreciated);
- your contact information for follow-up.
Our commitments
- We will acknowledge your report within 5 business days.
- We will keep you informed of remediation progress and tell you when the issue is fixed.
- We will not pursue legal action against research conducted in good faith under this policy (safe harbor).
What we ask
- Give us reasonable time to fix issues before public disclosure (we suggest 90 days).
- Do not access, modify, or exfiltrate data that isn't yours, if you encounter someone else's data, stop and report immediately.
- Do not degrade the Service for others.
- Do not use findings for extortion or demand payment as a condition of disclosure.
Recognition
We don't operate a paid bug bounty program at this time. We're glad to publicly thank researchers who make responsible disclosures, with your permission.