Security

Last reviewed: 6 August 2026 · Maintained by Pilot.

Pilot uses layered security controls intended to protect merchant, customer and platform information. Detailed internal controls are not published on this page.

Security principles

  • Least-privilege and deny-by-default access.
  • Tenant and role boundaries enforced by authoritative services.
  • Protected handling of credentials, tokens and cryptographic material.
  • Security logging, review and incident-response preparation.
  • Controlled release, rollback and evidence requirements.

Report a security concern

Send responsible security reports to security@pilotapp.io. In the initial message, provide a concise description and safe reproduction context, but do not send credentials, private keys, personal information or exploit data that is not necessary.

Responsible testing

Do not disrupt the service, access data that is not yours, bypass another user's account, perform destructive testing or publish a vulnerability before Pilot has had a reasonable opportunity to investigate. This page does not promise a bounty, payment or response SLA.