PentesterSpace
HomeBug BountySolutionsCareersPartnersCompanyPricing
Schedule a Meeting
Legal

Security & Disclosure

We build our business on finding vulnerabilities responsibly, so we hold ourselves to the same standard. If you have found a security issue in pentesterspace.com, this page explains how to tell us, what we commit to in return, and the protections you have when you follow it.

Effective September 3, 2026Pentester Space Ltd. · Dhaka, Bangladesh

Contents

  1. 1. How to Report
  2. 2. What to Include
  3. 3. What We Commit To
  4. 4. Safe Harbour
  5. 5. Scope
  6. 6. Rules
  7. 7. Findings We Generally Do Not Accept
  8. 8. Recognition
  9. 9. Coordinated Disclosure
  10. 10. Encryption
  11. 11. Contact

1. How to Report

Email security@pentesterspace.com with the details. This is the only channel we monitor for security reports — please do not use social media, support forms, or individual staff addresses.

A machine-readable version of this policy is published at /.well-known/security.txt in line with RFC 9116.

2. What to Include

The more precisely we can reproduce an issue, the faster we can fix it. Where possible, please tell us:

  • The URL, parameter, or component affected.
  • The type of issue, and clear steps to reproduce it.
  • What an attacker could achieve — the impact matters more to us than the class of bug.
  • Any proof of concept, request or response captures, or screenshots.
  • The date and time of your testing, and the source IP address you tested from, so we can match your activity to our logs.
  • How you would like to be credited, if we publish an acknowledgement.

Please send reports in English or Bengali.

3. What We Commit To

  • We acknowledge every report within 3 business days.
  • We give you an initial assessment, including whether we have accepted the finding, within 10 business days.
  • We keep you updated on remediation progress, and tell you when the issue is fixed.
  • We will not take legal action against you for research that follows this policy.
  • We will credit you for your finding if you would like us to, and will not disclose your identity without your permission.

4. Safe Harbour

If you make a good-faith effort to comply with this policy during your research, we will:

  • Consider your research authorised under applicable computer-misuse and anti-hacking laws, and will not bring or support a claim against you under them.
  • Consider your research authorised in relation to any anti-circumvention provisions, and will not bring a claim regarding circumvention of technical controls used to protect the scope of this policy.
  • Waive any restriction in our Terms of Service that would otherwise prohibit the security testing described here, to the limited extent necessary for that research.

If a third party brings legal action against you for research you carried out in accordance with this policy, we will make it known that your actions were authorised.

This protection applies only to the scope defined below, and only while you follow the rules in Section 6. It does not extend to systems operated by other parties, and we cannot authorise testing of infrastructure we do not control.

If you are ever unsure whether a specific action is permitted, stop and email us first. We would much rather answer a question than receive an apology.

5. Scope

In scope: the pentesterspace.com website and its content.

Everything else is out of scope, including:

  • Any other domain, subdomain, or host, whether or not it carries our name.
  • Any application, portal, or platform reached by a link from this website.
  • Systems belonging to our customers. These are covered by the individual Engagement Agreements that authorise our own testing, and no part of this policy authorises you to test them.
  • Third-party services we use, such as hosting, email, fonts, and content delivery. Report those to the provider under their own disclosure policy.
  • Physical premises, staff, suppliers, and anything reachable only through them.

If you believe you have found a serious issue in something outside this scope, tell us anyway — do not test it. We will route the report to whoever is responsible.

6. Rules

While researching an issue in scope, you must not:

  • Access, modify, download, or delete data that is not your own. If you encounter personal or customer data, stop immediately, do not save it, and tell us in your report.
  • Degrade, interrupt, or exhaust our services. Denial-of-service testing, load testing, and automated scanning at volume are not permitted.
  • Use social engineering, phishing, or physical intrusion against our staff, our customers, or our suppliers.
  • Move laterally, escalate access, or maintain persistence beyond the minimum needed to demonstrate the finding.
  • Publish, share, or retain any data obtained through your testing.

Keep proof of concept to the smallest demonstration that proves impact. A screenshot of a single record is evidence; a copy of the database is not.

7. Findings We Generally Do Not Accept

These are usually reported to us without a demonstrated impact. We will still read them, but they are unlikely to be accepted without a working attack scenario:

  • Missing security headers, cookie flags, or TLS configuration preferences with no demonstrated exploit.
  • Results copied from an automated scanner without validation.
  • Version disclosure, banner grabbing, or the mere presence of software with a published CVE, without showing it is exploitable here.
  • Missing rate limiting, or user enumeration, with no security consequence shown.
  • Self-XSS, clickjacking on pages with no sensitive action, or issues that require a compromised device or browser.
  • Best-practice recommendations and hardening suggestions with no security impact.
  • Vulnerabilities affecting only outdated or unsupported browsers.

8. Recognition

We recognise people who take the time to report an issue to us properly.

  • With your permission, we will credit you publicly for a valid finding, and we are glad to confirm your report in writing if that is useful to you professionally.
  • We may also offer a reward. Whether a reward is given, and in what form and amount, is decided by us alone, case by case.

Recognition and rewards are entirely at our discretion. This page is not a bug bounty programme and does not create an entitlement to payment. Where we do consider a reward, the factors that weigh most are the demonstrated impact of the issue, whether yours was the first report to identify it, and how clearly it was written and reproduced.

If several people report the same issue, we consider the first complete and reproducible report. Issues we already know about, and findings of the kind described in Section 7, are not normally eligible.

We cannot make a payment where doing so would breach applicable law or sanctions.

9. Coordinated Disclosure

Please give us 90 days from your report before disclosing publicly, and coordinate the timing with us. If we need longer for an issue that is genuinely complex to fix, we will explain why and agree a revised date with you rather than let it drift.

We will not ask you to stay silent indefinitely, and we will not treat a good-faith disclosure after an agreed date as a breach of this policy.

10. Encryption

If you would prefer to encrypt your report, contact us first at security@pentesterspace.com and we will supply a key.

11. Contact

Pentester Space Ltd.
15/A/10 New, West Rajabazar, Panthapath
Sher-e-Bangla Nagar, Dhaka 1215, Bangladesh
Security reports: security@pentesterspace.com
General inquiries: contact@pentesterspace.com

Related: our Privacy Policy and Terms of Service.

PentesterSpace

AI-native offensive security, backed by certified operators and a global researcher community.

Products

OqtrixAdversynTracefoldBug Bounty

Company

AboutCareersPartnersPricing

Contact

contact@pentesterspace.com+880 1885-610070ICT Tower, Agargaon, Dhaka
© 2026 PentesterSpace.
PrivacyTermsSecurity