Responsible disclosure
Draft — pending legal review.
Scope is everything
On Perbug, authorization is defined per project. Test only assets a project explicitly lists in scope. Anything in a project's out-of-scope list, or any system not covered by a project, is off limits.
Rules of engagement
No data destruction, no exfiltration beyond the minimum needed to prove a finding, no denial-of-service, no social engineering of a client's staff unless a project explicitly permits it. Respect NDAs.
Reporting Perbug itself
Found a bug in Perbug's own platform? Email security@perbug.com with repro steps. Good-faith research on our platform is welcome and will not be penalized. Do not access other users' data.
Safe harbor
Testing conducted in good faith and within a project's stated scope is authorized. Testing outside scope is not, and may carry legal consequences.