ProdgatorDocs

Reporting a security issue

How to report a security vulnerability in Prodgator, what is in and out of scope, and what to expect after you report one.

If you find a security vulnerability in Prodgator, tell us. We want to know about it and fix it.

How to report

Email security@prodgator.io. Please include:

  • A description of the issue and why it is a vulnerability.
  • Steps to reproduce it, or a proof of concept.
  • The URL, endpoint, or component involved.
  • Any tools or scripts you used.
  • Your contact details, so we can follow up and credit you if you want that.

Do not open a public GitHub issue for a security report. Email us instead so we can fix the issue before it is public.

This is also published as a security.txt file (RFC 9116) at on both and .

Scope

In scope:

  • The Prodgator web app ()
  • The Prodgator API
  • The Prodgator docs site ()
  • The Prodgator GitHub Action ()

Out of scope:

  • Social engineering of Prodgator staff, contractors, or customers
  • Denial of service or load testing
  • Vulnerabilities in third-party services we use or integrate with (report those to the vendor directly)
  • Findings that need physical access to a device you do not own

If you are not sure whether something is in scope, email us and ask.

Our commitments

  • We acknowledge new reports within 3 business days.
  • We keep you updated as we investigate and fix the issue.
  • We credit you in the fix notes or a security acknowledgment, if you want credit and it does not conflict with your own disclosure preferences.
  • We do not take legal action against good-faith security research that follows this policy.

Safe harbor

We consider security research conducted under this policy to be authorized. We will not pursue legal action against you for good-faith testing that:

  • Stays within the scope above.
  • Avoids privacy violations, data destruction, and service disruption.
  • Uses only accounts and data you own or have explicit permission to test with.
  • Gives us a reasonable chance to fix the issue before you disclose it publicly.

If a third party brings a claim against you for research that follows this policy, we will make it known that your research was authorized.

Bounty program

We do not run a paid bug bounty program right now. We still want your reports and will credit you as described above.

On this page