Security

Vulnerability disclosure policy

Last updated 18 August 2026. This page is a scaffold pending legal review — not a substitute for counsel-approved terms.

Scope

This policy covers vapentest.com, the VApentest application, and infrastructure we operate. Do not test customer targets or third-party systems unless you own them or have written authorization.

How to report

Send a description, affected URLs or versions, and steps to reproduce to security@vapentest.com. Do not include exploit payloads against production beyond what is needed to show impact.

What to expect

We aim to acknowledge reports within a few business days and to keep you updated while we investigate. Please give us a reasonable window to fix issues before public disclosure (90 days is a typical default unless we agree otherwise).