pbperbug

Responsible disclosure

Draft — pending legal review.

Scope is everything

On Perbug, authorization is defined per project. Test only assets a project explicitly lists in scope. Anything in a project's out-of-scope list, or any system not covered by a project, is off limits.

Rules of engagement

No data destruction, no exfiltration beyond the minimum needed to prove a finding, no denial-of-service, no social engineering of a client's staff unless a project explicitly permits it. Respect NDAs.

Reporting Perbug itself

Found a bug in Perbug's own platform? Email security@perbug.com with repro steps. Good-faith research on our platform is welcome and will not be penalized. Do not access other users' data.

Safe harbor

Testing conducted in good faith and within a project's stated scope is authorized. Testing outside scope is not, and may carry legal consequences.