Skip to main content

Vulnerability Disclosure

We take the security of Purradox Studio seriously and welcome responsible disclosure of potential vulnerabilities from the security research community.

How to Report

Email a detailed report of the suspected vulnerability to our security team. Please use a descriptive subject line such as [Vulnerability Report].

security@purradoxstudio.com

For encryption, request our PGP public key before sending sensitive details.

What to Include

  • A clear description of the issue and the specific page, URL, or feature affected.
  • Concrete steps to reproduce, including any input, configuration, or browser details required.
  • The potential impact and which category of user could be affected.
  • Suggested remediation or mitigations, if you have them.
  • Your contact information so we can follow up for clarification.

Prohibited Testing

  • Do not access, modify, exfiltrate, or destroy data belonging to other users.
  • Do not attempt to brute force, credential stuff, or deny service to the application.
  • Do not use automated scanners in a way that degrades service availability for others.
  • Do not target third-party services, payment providers, or infrastructure outside Purradox Studio.
  • Do not publicly disclose a reported issue before we have completed remediation.

Responsible Disclosure

  • We will acknowledge receipt of your report as soon as practical.
  • We will investigate and validate the report in good faith.
  • We ask that you give us reasonable time to remediate before any public disclosure.
  • We will notify you when the issue is resolved, when appropriate.
  • Please avoid any activity that could harm users or disrupt the service during investigation.

Acknowledgement

We appreciate responsible reports and may publicly thank credited researchers (with permission) once remediation is complete.

Purradox Studio does not offer a monetary bounty or reward program unless separately and explicitly authorized in writing. No guarantee of payment is implied by this policy.

Good-Faith Safe Harbor

We will not pursue legal action against researchers who follow this policy, act in good faith, avoid harm to users and the service, and respect the prohibited activities listed above. This safe harbor does not cover violations of law or this policy.

This policy is available at https://purradoxstudio.com/security and referenced from /.well-known/security.txt.