PantryBee Security Policy

Last updated: 3 September 2026

We build hardware with an unlocked bootloader and we expect people to take it apart. If you find a security problem, we want to hear about it.


Reporting

Email security@pantrybee.buzz.

Include what you can:

  • What you found and where.
  • Steps to reproduce.
  • What an attacker could do with it.
  • Firmware version, hardware revision, and app version, if relevant.

What to expect

Acknowledgment Within 3 business days
Initial assessment Within 10 business days
Progress updates Every 2 weeks until resolved
Credit We will name you in the fix announcement unless you prefer otherwise

We do not currently run a paid bounty program.


Safe harbor

If you follow this policy, we will not pursue legal action against you.

We will not bring or support a claim under the Computer Fraud and Abuse Act, the Digital Millennium Copyright Act, any state computer crime law, or our Terms of Service against a researcher acting in good faith under this policy. We consider your research authorized access.

If a third party brings action against you for research conducted under this policy, we will make it known that your activity was authorized.

Ground rules

To stay within the safe harbor:

  • Test only against your own account and your own Devices. Do not access another person's data.
  • Do not degrade the service. No denial of service, no volumetric testing, no spam.
  • Do not use social engineering against our users or staff, and no physical intrusion.
  • Stop when you have proof. Once you have demonstrated a vulnerability, stop — do not pivot, escalate, or exfiltrate more than needed to prove the finding.
  • If you encounter someone else's personal data, stop immediately, do not save or share it, and tell us in your report.
  • Give us time. See disclosure timing below.

Disclosure timing

We ask for 90 days before public disclosure, or until a fix ships, whichever comes first.

If we cannot fix something within 90 days we will tell you why and propose a timeline. If a vulnerability is being actively exploited, we will move faster and coordinate with you on early disclosure.

We will not ask you to delay disclosure indefinitely. If we go quiet or stop responding for 30 days, consider yourself released from the timeline.

What we consider in scope

  • The PantryBee backend and API
  • The GroceryBee mobile, Windows, and web applications
  • The GroceryBee firmware we publish and sign
  • The provisioning and activation flow
  • The over-the-air update mechanism

What is out of scope

  • Anything requiring physical possession of your own Device to exploit against itself. The bootloader is unlocked by design and flash is not encrypted. Extracting your own device token, your own Wi-Fi credentials, or our firmware image from your own hardware is expected behavior, not a vulnerability.

    If you find a way to use one device's extracted material against a different device or another user's account, that is very much in scope and we want to know immediately.

  • Third-party services we do not control — report those to their operators.

  • Reports from automated scanners without a demonstrated impact.

  • Missing security headers, TLS configuration preferences, and similar findings without a concrete exploitation path.

  • Social engineering and physical attacks.

  • Vulnerabilities in modified firmware you installed yourself.


Contact

PantryBee, LLC Security: security@pantrybee.buzz General: contact@pantrybee.buzz

← All legal documents
GroceryBee
The first product from PantryBee.
Contact
contact@pantrybee.buzz
Get notified →
Privacy Policy Terms of Service Terms of Sale & Limited Warranty Security Policy Open Source Attributions FCC Compliance All legal
© 2026 PantryBee, LLC · pantrybee.buzz · A PantryBee product