Security
Vulnerability disclosure policy
Last updated 18 August 2026. This page is a scaffold pending legal review — not a substitute for counsel-approved terms.
Scope
This policy covers vapentest.com, the VApentest application, and infrastructure we operate. Do not test customer targets or third-party systems unless you own them or have written authorization.
How to report
Send a description, affected URLs or versions, and steps to reproduce to security@vapentest.com. Do not include exploit payloads against production beyond what is needed to show impact.
What to expect
We aim to acknowledge reports within a few business days and to keep you updated while we investigate. Please give us a reasonable window to fix issues before public disclosure (90 days is a typical default unless we agree otherwise).