Security & compliance

Responsible disclosure

If you believe you have found a security vulnerability in Pact, we want to hear about it, and we will work with you to fix it. This page says how to report, what we commit to in return, and how we protect researchers who act in good faith.

How to report

Email security@pact.place with:

  1. what the issue is and where it is (host, page or API route);
  2. the steps to reproduce it, with the requests you sent;
  3. what an attacker could do with it;
  4. how we can reach you, and whether you would like to be credited.

Please do not include other people's personal data. If you came across some, tell us what kind it was and where, and delete your copy.

What we commit to

Acknowledgement
Within 2 business days
Updates
Through triage, fix and release
Disclosure window
90 days from acknowledgement

We may agree a different date with you. We move faster for critical issues, and we will credit you in the fix announcement if you want us to.

Scope

In scope

  • pact.place, app.pact.place and api.pact.place, including the public API
  • Sign-in, sessions, SSO, API keys and every other way of authenticating
  • One workspace reaching another workspace's data, or a role reaching beyond its permissions
  • Injection, cross-site scripting, request forgery and data exposure

Out of scope

  • Denial of service, load testing or anything that degrades the service for others
  • Social engineering of Pact staff or customers, and physical attacks
  • Our providers' own systems (hosting, payments, telephony, email, AI)
  • Workspaces you do not own, and customers' own domains
  • Scanner output without a working proof of concept

Test only against workspaces you own. To test whether one workspace can reach another, create two workspaces of your own. You never need a real customer's data to prove an issue.

Safe harbor

When you research and report in good faith under this policy, we consider your work authorized, and we will not bring legal action against you or ask law enforcement to act against you for it. We waive any restriction in our Terms of Service that would otherwise prohibit that research, to the extent needed to carry it out. If a third party brings a claim against you over research that followed this policy, we will make it known that your work was authorized.

Good faith means you:

If you are unsure whether something is allowed, email us first and ask.

Machine-readable version: /.well-known/security.txt (RFC 9116). Our wider security posture is on the security page and in the Trust Center.