Security
Responsible disclosure
We welcome reports from security researchers and commit to working with you to fix verified issues.
Reporting a vulnerability
If you believe you have found a security vulnerability in a website or service operated by BestPentesting or BugFoe Private Limited, please email sales@bugfoe.com with the subject line "Security Disclosure". Include a description of the issue, the affected URL or component, steps to reproduce, and any proof-of-concept.
Our commitments
- Acknowledge your report within three business days
- Keep you informed while we investigate and fix
- Not pursue legal action for good-faith research that follows this policy
- Credit you publicly if you wish, once the issue is resolved
Please do not
- Access, modify or delete data that isn't yours, beyond the minimum needed to demonstrate the issue
- Perform denial-of-service, spam or social engineering attacks
- Test third-party services we use, or our clients' systems
- Publicly disclose the issue before we have had a reasonable time to fix it
Machine-readable contact
Our security contact is also published at /.well-known/security.txt following RFC 9116.