Pabbly · Vulnerability Disclosure

Pabbly Vulnerability Disclosure

Vulnerability disclosure

Pabbly runs a coordinated vulnerability disclosure program on Hackerone.

AutomationEmail MarketingSubscription BillingBillingPaymentsWebhookMessagingWhatsAppEmail VerificationFormsNo-CodeSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

pabbly-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.pabbly.com/security-vulnerability-disclosure/
provider: Pabbly
providerId: pabbly
program:
  published: true
  name: Pabbly Security Vulnerability Disclosure Program
  url: https://www.pabbly.com/security-vulnerability-disclosure/
  mirror: https://buy.pabbly.com/security-vulnerability-disclosure/
  type: responsible-disclosure
  platform: self-hosted
  bug_bounty_platform: null
  note: >-
    Not on HackerOne, Bugcrowd or Intigriti — Pabbly runs the program itself and
    takes reports through its own form.
reporting:
  form: https://forms.pabbly.com/form/share/DPHw-722603307
  email_published: true
  email_obfuscated: true
  email_note: >-
    A reporting address is published on the page but is Cloudflare
    email-obfuscated in the markup, so it is not recorded verbatim here.
  security_txt: false
  security_txt_note: >-
    /.well-known/security.txt returned 404 on every Pabbly host — the program
    exists but is not machine-discoverable (see well-known/pabbly-well-known.yml).
scope:
  in_scope:
    - Pabbly web applications and services
  out_of_scope:
    - https://pabbly.hellonext.co
    - https://forum.pabbly.com
  qualifying:
    - authentication flaws
    - cross-site scripting (XSS)
    - server-side code execution
    - CORS / CSRF issues
  non_qualifying:
    - cookie flag issues
    - SPF / DKIM / DMARC configuration reports
    - denial-of-service attacks
safe_harbor:
  published: true
  language: >-
    "Do not cause any harm, hinder application fluency or act against our Terms
    of Use Agreement." Researchers must not access non-public data beyond what is
    needed to demonstrate the issue and must follow responsible disclosure.
response_commitment:
  acknowledgement: >-
    "We answer all submissions within a few days."
  fix_timeline: >-
    "Timelines for fixes will vary with the severity of the vulnerability and
    availability of engineering resources to address it."
rewards:
  offered: true
  discretionary: true
  maximum: 50
  currency: USD
  criteria:
    - severity
    - impact
    - originality
  payout_method: PayPal, after the fix ships, minus processing fees
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com