Reporting a security issue
How to report a security vulnerability in Prodgator, what is in and out of scope, and what to expect after you report one.
If you find a security vulnerability in Prodgator, tell us. We want to know about it and fix it.
How to report
Email security@prodgator.io. Please include:
- A description of the issue and why it is a vulnerability.
- Steps to reproduce it, or a proof of concept.
- The URL, endpoint, or component involved.
- Any tools or scripts you used.
- Your contact details, so we can follow up and credit you if you want that.
Do not open a public GitHub issue for a security report. Email us instead so we can fix the issue before it is public.
This is also published as a security.txt file (RFC 9116) at on both and .
Scope
In scope:
- The Prodgator web app ()
- The Prodgator API
- The Prodgator docs site ()
- The Prodgator GitHub Action ()
Out of scope:
- Social engineering of Prodgator staff, contractors, or customers
- Denial of service or load testing
- Vulnerabilities in third-party services we use or integrate with (report those to the vendor directly)
- Findings that need physical access to a device you do not own
If you are not sure whether something is in scope, email us and ask.
Our commitments
- We acknowledge new reports within 3 business days.
- We keep you updated as we investigate and fix the issue.
- We credit you in the fix notes or a security acknowledgment, if you want credit and it does not conflict with your own disclosure preferences.
- We do not take legal action against good-faith security research that follows this policy.
Safe harbor
We consider security research conducted under this policy to be authorized. We will not pursue legal action against you for good-faith testing that:
- Stays within the scope above.
- Avoids privacy violations, data destruction, and service disruption.
- Uses only accounts and data you own or have explicit permission to test with.
- Gives us a reasonable chance to fix the issue before you disclose it publicly.
If a third party brings a claim against you for research that follows this policy, we will make it known that your research was authorized.
Bounty program
We do not run a paid bug bounty program right now. We still want your reports and will credit you as described above.