Patravo Responsible Disclosure Policy
- Effective Date
- June 28, 2026
- Last Updated
- June 28, 2026
Contents
Patravo is operated by Venlorin LLC.
1. Plain-English Summary
Patravo welcomes good-faith security reports.
Patravo is used by youth-serving organizations, including troops, packs, crews, ships, posts, councils, chartered organizations, camps, schools, churches, clubs, nonprofits, and similar groups. Because Patravo may contain youth, parent, guardian, leader, volunteer, organization, event, communication, and media information, security research involving Patravo must be careful, limited, and privacy-protective.
This policy explains how to report security vulnerabilities to Patravo safely and responsibly.
The most important rules are:
- Report security issues to security@patravo.com.
- Test only systems that Patravo owns or operates.
- Use only accounts, workspaces, and data you own or are clearly authorized to test.
- Do not access, download, copy, change, delete, expose, or misuse real user data.
- Do not access youth data, parent or guardian data, rosters, private messages, photos, videos, attendance records, emergency information, payment information, credentials, secrets, or organization records.
- Stop testing immediately if you encounter sensitive information.
- Do not disrupt Patravo, degrade safety features, interfere with communications, or test denial-of-service conditions.
- Do not conduct social engineering, phishing, smishing, vishing, physical attacks, credential stuffing, or attacks against users, families, leaders, volunteers, staff, councils, chartered organizations, or third-party providers.
- Do not publicly disclose a vulnerability until Patravo gives written permission.
- Responsible disclosure is not a bug bounty program. Patravo does not currently offer cash rewards unless a separate written bug bounty program says otherwise.
If you follow this policy in good faith, Patravo will treat your research as authorized security research, as described in the safe-harbor section below.
2. Purpose of This Policy
This Responsible Disclosure Policy, also known as a vulnerability disclosure policy, is designed to help security researchers, customers, users, administrators, parents, guardians, and others report security concerns safely.
The goals of this policy are to:
- Protect youth members, families, adult leaders, volunteers, organizations, councils, chartered organizations, and other Patravo users.
- Create a clear way to report security vulnerabilities.
- Set boundaries for safe and responsible testing.
- Reduce the risk of privacy harm.
- Reduce the risk of service disruption.
- Help Patravo investigate, verify, prioritize, and fix valid security issues.
- Support coordinated disclosure when appropriate.
- Encourage good-faith research without allowing harmful conduct.
Patravo appreciates responsible security research. We also take youth safety, family privacy, organization privacy, and platform integrity seriously.
3. Who This Policy Applies To
This policy applies to anyone who reports or researches a potential security vulnerability involving Patravo, including:
- Independent security researchers
- Patravo customers
- Organization owners
- Organization administrators
- Adult leaders
- Volunteers
- Parents and guardians
- Youth users who accidentally discover a security issue
- Website visitors
- Vendors and contractors, unless a separate agreement applies
- Anyone else who reports a security issue to Patravo
Patravo employees, contractors, and vendors may also have separate internal reporting duties and procedures.
If you are under 18 and discover a security issue, do not continue testing. Report the issue to a parent, guardian, trusted adult, organization leader, or Patravo at security@patravo.com.
4. In-Scope Systems
This policy applies only to systems owned or operated by Patravo.
The following systems are in scope:
- https://patravo.com
- Patravo web app
- Patravo iOS app
- Patravo Android app
- Patravo-owned APIs
- Patravo authentication flows
- Patravo organization workspaces
- Patravo public organization website features
- Patravo file and media upload systems
- Patravo role, permission, and organization access-control systems
- Patravo youth-protection settings and related safeguards
- Patravo notification systems, to the extent controlled by Patravo
- Patravo-owned infrastructure configurations, to the extent they are visible from Patravo-controlled systems
Only test systems you reasonably believe are owned or operated by Patravo.
If you are not sure whether a system is in scope, ask first by emailing security@patravo.com.
5. Out-of-Scope Systems
This policy does not authorize testing against systems that Patravo does not own or operate.
The following are out of scope unless Patravo gives you written permission:
- Scouting America systems
- Council systems
- District systems
- Chartered organization systems
- Customer-owned websites or domains not hosted by Patravo
- School, church, nonprofit, club, camp, or community organization systems
- App store systems
- Payment processor systems
- Email delivery provider systems
- Push notification provider systems
- Authentication provider systems
- Cloud provider systems, except Patravo-controlled configurations
- Third-party APIs or integrations
- Personal devices or accounts of users, youth members, parents, guardians, leaders, volunteers, council staff, chartered organization representatives, or Patravo staff
- Physical offices, facilities, camps, events, or locations
- Venlorin LLC systems unrelated to Patravo, unless specifically identified as in scope
Do not test third-party systems just because Patravo uses or integrates with them.
If you believe a vulnerability affects a third-party service used by Patravo, report it to Patravo and, where appropriate, to the third party under that third party’s vulnerability disclosure process.
6. Activities That Are Not Allowed
This policy does not authorize harmful, invasive, deceptive, disruptive, or unsafe activity.
You may not:
- Access accounts that are not yours.
- Access data that is not yours.
- Access youth data.
- Access parent or guardian data.
- Access organization rosters.
- Access private messages, group messages, files, photos, videos, attendance records, consent records, emergency information, billing information, credentials, tokens, secrets, or logs.
- Download, copy, save, retain, publish, sell, share, or disclose real user data.
- Modify or delete data that is not yours.
- Create, alter, or delete real organization records.
- Create fake accounts that impersonate youth members, parents, guardians, adult leaders, council staff, chartered organization representatives, Scouting America representatives, Patravo staff, or other real people.
- Bypass youth-protection settings for real users.
- Create hidden or unsupervised adult-to-youth communication spaces.
- Attempt to access or expose private youth, family, or organization information.
- Conduct social engineering.
- Conduct phishing, smishing, or vishing.
- Contact, deceive, pressure, or manipulate Patravo users, youth members, parents, guardians, leaders, volunteers, staff, councils, chartered organizations, or service providers.
- Use stolen, leaked, guessed, purchased, or reused credentials.
- Conduct credential stuffing.
- Conduct password spraying.
- Conduct brute-force attacks.
- Conduct denial-of-service testing.
- Conduct load testing.
- Send spam.
- Upload malware, ransomware, spyware, viruses, worms, or destructive code.
- Attempt persistence.
- Move laterally inside systems.
- Exfiltrate data.
- Attempt to bypass rate limits in a way that could affect service reliability.
- Interfere with service availability, safety features, communications, events, notifications, payments, or account access.
- Test physical security.
- Attack employees, contractors, vendors, users, families, councils, chartered organizations, or third-party providers.
- Threaten public disclosure to pressure Patravo.
- Demand payment, ransom, employment, contract work, or other compensation in exchange for not disclosing or exploiting a vulnerability.
- Sell, broker, trade, or transfer vulnerability information.
- Publicly disclose a vulnerability before Patravo gives written permission.
- Violate the law.
- Violate third-party terms.
- Violate app store rules.
- Use a vulnerability for personal gain.
- Continue testing after Patravo asks you to stop.
If your testing may affect real users, real organizations, youth safety, private data, or service availability, do not perform that testing.
7. Youth Safety and Sensitive Data Rules
Patravo is used by youth-serving organizations. This creates a higher standard for responsible research.
You must not intentionally access, view, download, copy, store, share, modify, or delete:
- Youth member information
- Parent or guardian information
- Adult leader or volunteer information
- Organization rosters
- Patrol, den, group, crew, troop, pack, ship, post, committee, council, or chartered organization records
- Private messages
- Group messages
- Event discussions
- Attendance records
- RSVP records
- Consent records
- Permission information
- Emergency contact information
- Medical notes
- Allergy information
- Transportation information
- Photos or videos
- File attachments
- Billing information
- Authentication tokens
- API keys
- Session cookies
- Passwords
- Private keys
- Internal logs
- Any other sensitive personal or organization information
If you encounter sensitive information by accident:
- Stop testing immediately.
- Do not continue exploring.
- Do not download or copy the information.
- Do not take screenshots that reveal personal information unless absolutely necessary, and redact them if possible.
- Do not share the information with anyone except Patravo.
- Report the issue promptly to security@patravo.com.
- Delete any local copies, notes, screenshots, logs, or files that contain sensitive information unless Patravo or law requires preservation.
Your report should include only the minimum information needed for Patravo to understand and reproduce the issue safely.
8. Authorized Research and Safe Harbor
Patravo supports good-faith security research that follows this policy.
If you comply with this policy, Patravo will consider your research authorized and will not knowingly initiate legal action against you for that research.
To qualify for this safe harbor, your research must:
- Be limited to in-scope Patravo systems.
- Follow this policy.
- Be conducted in good faith.
- Use only accounts, workspaces, and data you own or are clearly authorized to test.
- Avoid privacy harm.
- Avoid youth-safety risks.
- Avoid accessing or exposing real user data.
- Avoid disruption or degradation of the Service.
- Avoid deception, social engineering, phishing, credential attacks, or physical attacks.
- Be reported promptly to Patravo.
- Be kept confidential until Patravo gives written permission for disclosure.
- Not involve extortion, threats, ransom, public pressure, or misuse of vulnerability information.
If a third party initiates legal action against you for research that Patravo determines was conducted in compliance with this policy, Patravo may state that your research was authorized under this policy.
This safe harbor does not apply to conduct that violates this policy.
This policy does not give you permission to violate the law, access data that is not yours, attack third-party systems, or ignore instructions from Patravo to stop testing.
9. Recommended Testing Approach
When testing Patravo, use the least invasive method possible.
Recommended practices:
- Use your own account.
- Use your own email address.
- Use a test organization that you created and control.
- Use fake test data.
- Use generic test names.
- Use non-sensitive images and files.
- Keep test volume low.
- Use manual testing where practical.
- Avoid automated scans unless they are low-volume, non-destructive, and do not affect service availability.
- Stop immediately if anything unexpected happens.
- Report suspected vulnerabilities promptly.
Do not create test data that pretends to be a real youth member, parent, guardian, troop leader, council employee, chartered organization representative, Scouting America representative, or Patravo staff member.
Suggested test organization naming pattern:
Security Test Organization - [Your Name or Handle]
Suggested test user naming pattern:
Security Test User - [Role]
Do not use real youth names, real organization names, real scouting unit numbers, real council names, or real chartered organization names in security testing unless you are explicitly authorized to test that organization’s Patravo workspace.
10. Examples of Vulnerabilities We Want Reported
Patravo wants to hear about security issues that could affect confidentiality, integrity, availability, youth safety, organization privacy, account security, or platform trust.
Examples include:
- Authentication bypass
- Authorization bypass
- Account takeover
- Privilege escalation
- Broken access control
- Cross-organization data exposure
- Insecure direct object references
- Youth or guardian data exposure
- Roster exposure
- Message visibility errors
- File or media access-control failures
- Public/private sharing bypasses
- Unauthorized access to attendance records
- Unauthorized access to consent or permission records
- Unauthorized access to emergency or medical information
- Vulnerabilities that bypass youth-protection settings
- Vulnerabilities that allow secret adult-to-youth communication where youth-protection settings should prevent it
- Vulnerabilities that allow unauthorized public publishing
- Insecure password reset flows
- Multi-factor authentication bypasses, if applicable
- Session fixation or session hijacking
- Token leakage
- API key exposure
- Server-side request forgery
- Remote code execution
- SQL injection
- Command injection
- Cross-site scripting with meaningful security impact
- Cross-site request forgery with meaningful security impact
- Sensitive information disclosure
- Misconfigured storage buckets or object permissions
- Insecure file upload
- Permission errors in organization administration
- Vulnerabilities exposing payment, billing, or subscription data
- Vulnerabilities that could allow unauthorized modification or deletion of organization records
This list is not exhaustive. If you are unsure whether something is worth reporting, report it.
11. Low-Priority or Usually Out-of-Scope Reports
Some reports are usually low priority unless they show a practical security impact.
Examples include:
- Automated scanner output without validation
- Missing security headers without demonstrated exploitability
- Best-practice-only TLS findings
- Cookie flags without meaningful exploitability
- Clickjacking on non-sensitive pages
- Logout cross-site request forgery
- Self-XSS
- Open redirects without meaningful security impact
- Username enumeration without a practical attack path
- Rate-limit concerns without a realistic abuse scenario
- Reports about outdated libraries without exploitable impact
- SPF, DKIM, or DMARC concerns without demonstrated impact
- Physical access attacks against an unlocked device
- Reports requiring malware on a user’s device
- Reports requiring a fully compromised account
- Social engineering-only findings
- Theoretical issues without proof of impact
- Issues affecting third-party systems outside Patravo’s control
- Public information exposure where the information was intentionally published by an organization
Patravo may still review these reports, especially if they involve youth safety, organization privacy, or sensitive information.
12. How to Submit a Report
Send security reports to:
Please include:
- Your name or handle
- Your contact email
- The affected URL, app, endpoint, feature, or version
- The type of vulnerability
- Clear steps to reproduce the issue
- The impact of the issue
- Whether youth, parent, guardian, leader, volunteer, organization, payment, credential, or other sensitive data may be affected
- Whether any data was accessed, copied, modified, deleted, or exposed
- Screenshots, logs, or proof-of-concept details, only when safe and minimally necessary
- Suggested remediation, if known
- Whether you want public recognition if Patravo later chooses to provide acknowledgments
Use the subject line:
Security Report - [Brief Description]
Examples:
Security Report - Organization File Access Control Issue
Security Report - Possible Account Takeover in Password Reset Flow
Security Report - Youth Visibility Permission Bypass
13. What Not to Include in a Report
Do not send unnecessary sensitive information.
Do not include:
- Full youth records
- Full parent or guardian records
- Full rosters
- Full private messages
- Full event records
- Full attendance records
- Full consent records
- Full medical or emergency information
- Full photos or videos
- Full file contents
- Full payment information
- Passwords
- Session tokens
- Private keys
- API keys
- Large data dumps
- Malware
- Ransomware
- Weaponized exploit code
- Instructions for harming users or disrupting the Service
If sensitive information is necessary to explain the issue, redact it as much as possible.
14. Patravo’s Response Process
Patravo takes security reports seriously.
After receiving a report, Patravo will generally work through the following process:
- Acknowledge the report.
- Review the report for scope and safety.
- Ask follow-up questions if needed.
- Attempt to reproduce and validate the issue.
- Assess severity and user impact.
- Prioritize remediation.
- Work on a fix, mitigation, configuration change, vendor escalation, app update, or other response.
- Notify affected organizations, users, service providers, app stores, law enforcement, child protection agencies, or other parties when legally required or reasonably necessary.
- Provide the researcher with an update where appropriate.
- Close the report when the issue is resolved, accepted as risk, found invalid, found duplicate, or determined out of scope.
Patravo aims to acknowledge security reports within a reasonable period. Complex issues may take longer to investigate and fix, especially when they involve mobile app updates, third-party providers, infrastructure changes, legal review, youth safety, or customer notification.
Patravo does not guarantee a specific response time or resolution time unless a separate written agreement says otherwise.
15. Severity and Prioritization
Patravo prioritizes security issues based on risk.
Factors may include:
- Risk to youth members
- Risk to parents or guardians
- Risk to adult leaders or volunteers
- Risk to organization rosters
- Risk to private communications
- Risk to photos, videos, files, or media
- Risk to attendance, permission, emergency, or medical information
- Risk to accounts or authentication
- Risk of cross-organization access
- Risk of unauthorized public disclosure
- Risk of bypassing youth-protection settings
- Risk of unauthorized adult-to-youth communication
- Risk of data modification or deletion
- Risk to payments or billing
- Exploitability
- Whether exploitation is active
- Number of affected users or organizations
- Legal, regulatory, or contractual impact
- Availability impact
- Vendor or third-party dependencies
- Whether a temporary mitigation is available
Youth-safety impact is a major severity factor for Patravo.
A vulnerability that might be moderate on a general-purpose platform may be treated as higher severity if it could expose youth information, bypass guardian visibility, weaken organization oversight, or allow unsafe communication.
16. Coordinated Disclosure
Patravo supports coordinated disclosure.
You agree not to publicly disclose a vulnerability, proof of concept, exploit method, screenshot, video, technical details, or related information until Patravo gives written permission.
This includes disclosure through:
- Blogs
- Social media
- Forums
- Chat servers
- Video platforms
- Security conferences
- Vulnerability databases
- Mailing lists
- Public repositories
- Press or media outlets
- Customers or users
- Third parties not involved in remediation
Patravo may coordinate public disclosure when appropriate.
Patravo may delay or decline public disclosure when disclosure could create risk to youth members, families, organizations, active systems, law enforcement investigations, child-safety investigations, or unresolved vulnerabilities.
If public disclosure is approved, Patravo may request that disclosure avoid:
- User-identifying information
- Organization-identifying information
- Youth information
- Exploit-ready detail
- Sensitive screenshots
- Information that would enable copycat attacks
Patravo values transparency, but youth safety and privacy come first.
17. Recognition and Rewards
Patravo appreciates good-faith security reports.
Patravo may choose to acknowledge researchers publicly if:
- The report is valid.
- The researcher followed this policy.
- The researcher wants recognition.
- Public recognition would not create safety, legal, privacy, or security risk.
Patravo does not currently offer cash bounties.
Submitting a report does not create a right to:
- Payment
- Reward
- Employment
- Contract work
- Consulting work
- Public recognition
- Swag
- Future access
- Continued testing authorization
Patravo may decline recognition for reports involving unsafe conduct, policy violations, privacy harm, public disclosure without permission, extortion, threats, or bad-faith activity.
18. Privacy and Data Handling
Patravo will use security report information to investigate, verify, fix, mitigate, document, and improve the Service.
Patravo may share report details with:
- Patravo personnel
- Venlorin LLC personnel
- Contractors helping with security or remediation
- Service providers or subprocessors
- Cloud, app store, payment, authentication, email, push, or infrastructure providers
- Legal counsel
- Affected organizations
- Affected users
- Law enforcement
- Child protection agencies
- Child-safety organizations
- Regulators or authorities, when required or appropriate
Patravo will try to limit sharing to what is reasonably necessary.
Researchers must treat vulnerability information as confidential until Patravo gives written permission for disclosure.
Researchers must not retain sensitive user, youth, family, organization, credential, payment, or internal data after reporting, except as required by law.
19. Emergency and Child-Safety Reports
If you discover evidence of child exploitation, grooming, abuse, coercion, threats, self-harm risk, violence, or immediate danger, stop testing immediately.
If there is an emergency or immediate risk of harm, contact emergency services or the appropriate authorities first.
Then notify Patravo at:
or, for non-technical safety concerns:
Patravo may preserve records and report to appropriate authorities, affected organizations, parents, guardians, councils, chartered organizations, law enforcement, child protection agencies, or child-safety organizations when legally required or reasonably necessary.
Do not investigate child-safety incidents yourself through unauthorized access, impersonation, surveillance, deception, or continued testing.
20. Mobile App Research
Patravo’s iOS and Android apps are in scope only to the extent they are Patravo-controlled applications and your research follows this policy.
Permitted research may include limited, good-faith testing of Patravo app behavior, authentication, authorization, data storage, transport security, and API interactions using your own account and test data.
This policy does not authorize you to:
- Violate Apple App Store terms.
- Violate Google Play terms.
- Circumvent device, app store, or platform protections unlawfully.
- Attack app store infrastructure.
- Attack third-party SDK providers.
- Extract secrets or data from accounts you do not control.
- Distribute modified Patravo apps.
- Mislead users into installing modified apps.
- Use mobile research to access real youth, family, organization, or user data.
Report mobile vulnerabilities with the app version, device type, operating system version, and steps to reproduce.
21. No Permission to Violate Other Rules
This policy does not authorize you to:
- Break the law.
- Access data that is not yours.
- Attack third-party systems.
- Violate third-party terms.
- Violate app store rules.
- Violate Patravo’s Terms of Service except to the limited extent necessary for authorized research under this policy.
- Conduct social engineering.
- Conduct physical intrusion.
- Conduct denial-of-service testing.
- Conduct credential attacks.
- Exfiltrate data.
- Publish vulnerability details without written permission.
- Harm users, organizations, Patravo, Venlorin LLC, or the public.
If you are unsure whether an action is allowed, do not perform it. Ask first at security@patravo.com.
22. Loss of Safe Harbor
Safe harbor does not apply if you:
- Act maliciously.
- Access data that is not yours.
- Access youth data.
- Access parent or guardian data.
- Access organization records without authorization.
- Exfiltrate data.
- Modify or delete data without authorization.
- Disrupt the Service.
- Test outside scope.
- Attack third-party systems.
- Use social engineering.
- Use phishing, smishing, or vishing.
- Use credential stuffing, password spraying, brute force, stolen credentials, or credential theft.
- Upload malware or destructive code.
- Attempt extortion.
- Demand payment.
- Threaten public disclosure.
- Publicly disclose without written permission.
- Sell, share, or broker vulnerability information.
- Continue testing after being asked to stop.
- Misrepresent your identity or authority.
- Harm users, organizations, youth members, families, Patravo, Venlorin LLC, or the public.
- Violate this policy.
Patravo may take legal, technical, safety, account, organizational, or reporting action when research falls outside this policy.
23. No Bug Bounty Program
This Responsible Disclosure Policy is not a bug bounty program.
Patravo does not currently pay cash rewards for vulnerability reports unless Patravo separately announces a written bug bounty program.
Do not demand payment, threaten disclosure, threaten exploitation, or condition cooperation on compensation.
Reports submitted under this policy are voluntary.
24. Security.txt
Patravo may publish a machine-readable security.txt file at:
https://patravo.com/.well-known/security.txt
Recommended contents:
Contact: mailto:security@patravo.com
Policy: https://patravo.com/legal/responsible-disclosure
Preferred-Languages: en
Canonical: https://patravo.com/.well-known/security.txt
Expires: [update before expiration]
Patravo may add fields such as encryption, acknowledgments, or hiring links if those programs become available.
Do not rely on a PGP key, acknowledgments page, hiring page, or bounty page unless Patravo has actually published one.
25. Changes to This Policy
Patravo may update this Responsible Disclosure Policy from time to time.
Every update receives a version number.
Current and previous versions are available at:
https://patravo.com/legal/responsible-disclosure/versions
Material changes are described in the changelog at:
https://patravo.com/legal/responsible-disclosure/changelog
Changes apply prospectively. Research conducted before a change will be evaluated under the policy in effect at the time of the research, unless the updated policy is more protective of the researcher and Patravo determines it is appropriate to apply it.
If you are actively researching or reporting an issue, you are responsible for reviewing the current version of this policy.
26. Contact
Security reports should be sent to:
Other contacts:
Venlorin LLC
522 W Riverside Ave Ste N
Spokane, WA 99201
United States
Website: https://patravo.com
Security: security@patravo.com
Support: support@patravo.com
Privacy: privacy@patravo.com
For urgent danger or immediate risk of harm, contact emergency services or appropriate authorities first, then notify Patravo as appropriate.