Vulnerability Disclosure Policy

We welcome reports from security researchers. This policy explains how to report a vulnerability in PentestHub AI and what you can expect from us.

How to report

Email security@pentesthubai.com or use "Report a vulnerability" (private advisory) on our GitHub repository. Please do not open a public issue. Include the affected URL or component, steps to reproduce, the impact and any proof of concept. Our machine-readable contact details are published at /.well-known/security.txt.

What we commit to

  • Acknowledge your report within 5 business days.
  • Keep you informed while we investigate and fix the issue.
  • Coordinate public disclosure with you once a fix is available.
  • Credit you in the advisory if you wish.

Rules for testing our platform

  • Use only your own accounts and data.
  • No denial-of-service, spam, or social engineering of our staff or users.
  • Do not access, change or delete other users' data. Stop as soon as you can demonstrate impact.
  • Give us a reasonable time to fix the issue before any public disclosure.

Safe harbor

If you act in good faith and follow this policy, we will consider your research authorized and will not initiate legal action against you for it.

Out of scope

  • Findings from automated scanners without a demonstrated impact.
  • Missing best-practice headers or settings without a concrete exploit.
  • Issues in third-party services we use, which should be reported to those vendors.