Security & Vulnerability Disclosure
We welcome reports of security vulnerabilities in PentestHub AI. The full policy is on the Security page.
How to report
- Email security@pentesthubai.com, or
- use Report a vulnerability on the project's GitHub repository (private advisory).
Please do not open a public issue for a security problem.
Include the affected URL or component, steps to reproduce, the impact you observed and any proof of concept. Our machine-readable contact details are in /.well-known/security.txt.
What to expect
- Acknowledgement within 5 business days.
- Updates as we investigate, and coordinated disclosure once a fix is available.
- Credit in the advisory if you want it.
Testing rules for our platform
- Test only with your own accounts and data.
- No denial-of-service, spam or social engineering of our staff or users.
- Do not access, change or delete other users' data; stop and report as soon as you can show impact.
Reports made in good faith under these rules will not be pursued legally by us.