Responsible disclosure
If you believe you have found a security vulnerability in Pact, we want to hear about it, and we will work with you to fix it. This page says how to report, what we commit to in return, and how we protect researchers who act in good faith.
How to report
Email security@pact.place with:
- what the issue is and where it is (host, page or API route);
- the steps to reproduce it, with the requests you sent;
- what an attacker could do with it;
- how we can reach you, and whether you would like to be credited.
Please do not include other people's personal data. If you came across some, tell us what kind it was and where, and delete your copy.
What we commit to
- Acknowledgement
- Within 2 business days
- Updates
- Through triage, fix and release
- Disclosure window
- 90 days from acknowledgement
We may agree a different date with you. We move faster for critical issues, and we will credit you in the fix announcement if you want us to.
Scope
In scope
- pact.place, app.pact.place and api.pact.place, including the public API
- Sign-in, sessions, SSO, API keys and every other way of authenticating
- One workspace reaching another workspace's data, or a role reaching beyond its permissions
- Injection, cross-site scripting, request forgery and data exposure
Out of scope
- Denial of service, load testing or anything that degrades the service for others
- Social engineering of Pact staff or customers, and physical attacks
- Our providers' own systems (hosting, payments, telephony, email, AI)
- Workspaces you do not own, and customers' own domains
- Scanner output without a working proof of concept
Test only against workspaces you own. To test whether one workspace can reach another, create two workspaces of your own. You never need a real customer's data to prove an issue.
Safe harbor
When you research and report in good faith under this policy, we consider your work authorized, and we will not bring legal action against you or ask law enforcement to act against you for it. We waive any restriction in our Terms of Service that would otherwise prohibit that research, to the extent needed to carry it out. If a third party brings a claim against you over research that followed this policy, we will make it known that your work was authorized.
Good faith means you:
- stop as soon as you have shown the issue, and access no more data than you need to;
- do not change, destroy or keep data that is not yours;
- do not degrade the service for anyone else;
- give us the disclosure window above before telling anyone else, and do not ask for payment as a condition of reporting.
If you are unsure whether something is allowed, email us first and ask.
Machine-readable version: /.well-known/security.txt (RFC 9116). Our wider security posture is on the security page and in the Trust Center.