ProdgatorDocs

Reporting a security issue

How to report a security vulnerability in Prodgator, what is in and out of scope, and what to expect after you report one.

Pas encore traduite. Cette page est affichée en anglais. Lire l’original en anglais.

If you find a security vulnerability in Prodgator, tell us. We want to know about it and fix it.

How to report

Email security@prodgator.io. Please include:

  • A description of the issue and why it is a vulnerability.
  • Steps to reproduce it, or a proof of concept.
  • The URL, endpoint, or component involved.
  • Any tools or scripts you used.
  • Your contact details, so we can follow up and credit you if you want that.

Do not open a public GitHub issue for a security report. Email us instead so we can fix the issue before it is public.

This is also published as a security.txt file (RFC 9116) at on both and .

Scope

In scope:

  • The Prodgator web app ()
  • The Prodgator API
  • The Prodgator docs site ()
  • The Prodgator GitHub Action ()

Out of scope:

  • Social engineering of Prodgator staff, contractors, or customers
  • Denial of service or load testing
  • Vulnerabilities in third-party services we use or integrate with (report those to the vendor directly)
  • Findings that need physical access to a device you do not own

If you are not sure whether something is in scope, email us and ask.

Our commitments

  • We acknowledge new reports within 3 business days.
  • We keep you updated as we investigate and fix the issue.
  • We credit you in the fix notes or a security acknowledgment, if you want credit and it does not conflict with your own disclosure preferences.
  • We do not take legal action against good-faith security research that follows this policy.

Safe harbor

We consider security research conducted under this policy to be authorized. We will not pursue legal action against you for good-faith testing that:

  • Stays within the scope above.
  • Avoids privacy violations, data destruction, and service disruption.
  • Uses only accounts and data you own or have explicit permission to test with.
  • Gives us a reasonable chance to fix the issue before you disclose it publicly.

If a third party brings a claim against you for research that follows this policy, we will make it known that your research was authorized.

Bounty program

We do not run a paid bug bounty program right now. We still want your reports and will credit you as described above.

Sur cette page