← Back to home

    Security & Vulnerability Reporting

    Last updated: August 14, 2026Version 2026-08-14

    Sustainable Life Investments, LLC ("SLI", "we", "us") operates sustainablelifeinvestments.com and parkpillow.com. We take the security of guest data seriously, and we welcome reports from security researchers acting in good faith. This page describes our practices, our disclosure policy, and the safe harbor we extend to researchers who follow it.

    1. Report a Vulnerability

    Security contact

    hello@sustainablelifeinvestments.com — subject line "Security"

    Please include: what you found, where, the steps to reproduce it, its impact, and any proof of concept. Let us know if you want credit for the finding.

    Our commitment: we acknowledge a report within 3 business days, give you an initial assessment within 10 business days, keep you updated while we work, and tell you when it is fixed. We do not run a paid bug-bounty program, but we are glad to credit researchers publicly with their permission.

    2. Safe Harbor

    If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, we will not pursue or support legal action against you under the Computer Fraud and Abuse Act, Florida's computer-crime statutes, or the anti-circumvention provisions of the DMCA, and we will not treat your activity as a breach of our Terms of Service or Acceptable Use Policy. If a third party brings legal action against you for research conducted in compliance with this policy, we will make that compliance known.

    Safe harbor does not extend to activity that violates the rules below, and it cannot bind anyone other than SLI.

    3. Rules of Engagement

    Please do:

    • Test only against accounts and data you own or that we have provided for testing.
    • Stop as soon as you confirm a vulnerability, and report it.
    • Limit the number of requests you send, and test at a volume that will not affect other guests.
    • Give us a reasonable time to fix an issue before disclosing it publicly — 90 days is our default, and we are happy to agree on something shorter for a low-risk issue.

    Please do not:

    • Access, download, modify, or retain another person's data. If you encounter guest data, stop immediately, do not save it, and tell us what you saw so we can assess the exposure.
    • Run denial-of-service, load, brute-force, or credential-stuffing tests.
    • Use social engineering, phishing, or physical intrusion against our team, guests, or properties.
    • Install a backdoor, pivot to other systems, or maintain persistence.
    • Test against our vendors' infrastructure directly, or against any property, lock, or on-site device.
    • Demand payment in exchange for withholding a report — that is extortion, not research, and is outside this policy.

    4. In Scope

    • sustainablelifeinvestments.com and parkpillow.com, including the guest account area, availability search, e-check-in, and public API routes.
    • Authentication, session handling, and access-control flaws, including any way to reach another guest's reservation, messages, rewards balance, or ID image.
    • Injection, cross-site scripting, server-side request forgery, insecure direct object references, and data exposure through misconfigured access rules.

    5. Out of Scope

    • Missing security headers, cookie flags, or TLS configuration nits with no demonstrated impact.
    • Rate-limiting or brute-force findings without a working proof of concept.
    • Automated scanner output with no manual validation.
    • Social engineering, spam, or self-XSS.
    • Vulnerabilities in third-party platforms (Airbnb, Vrbo, Booking.com) — report those to the platform.
    • Issues requiring a rooted or physically compromised device, or an outdated browser.

    6. How We Protect Guest Data

    • All traffic is served over TLS.
    • Sensitive guest fields — date of birth, emergency phone, and email address — are encrypted at rest with AES-256-GCM using keys we control.
    • Government ID images are stored in a private bucket with no public URLs, with image metadata stripped, and are deleted no later than 12 months after checkout.
    • Access is enforced in the database itself with row-level security, not only in the application, and administrative roles live in a dedicated roles table checked server-side.
    • Administrative access to sensitive guest fields is written to an audit log with the administrator's identity and a timestamp.
    • Input is validated and sanitized on the server, and secrets are held in the server runtime, never in browser code.

    Full detail on our data practices is in the Privacy Policy. No system is perfectly secure, and nothing on this page is a warranty or guarantee of security.

    7. Breach Notification

    If a security incident affects your personal information, we will notify you and the applicable authorities as required by Florida's data-breach statute, section 501.171, Florida Statutes, and any other law that applies to you, without unreasonable delay.

    8. Guest Security Tips

    • Your check-in link, reservation link, and rewards magic link are bearer credentials — anyone holding one can open what it points to. Do not forward them.
    • We will never ask for your password, a full payment card number, or a code by text or phone.
    • Email from us always comes from a parkpillow.com or sustainablelifeinvestments.com address. When in doubt, forward it to us before acting on it.

    All policies

    Sustainable Life Investments, LLC operates sustainablelifeinvestments.com and parkpillow.com. Questions about any policy on this page: hello@parkpillow.com.