Docs

Responsible disclosure

Found something? Here is how to tell us.

If you have found a security issue, we want to hear about it. Email info@pressbotics.com with "Security" in the subject. Please report privately first rather than publishing.

What to include

  • What the issue is, and the impact you believe it has.
  • Steps to reproduce, precise enough for us to follow.
  • The affected URL or endpoint, and roughly when you tested.
  • Whether you accessed any data that was not yours, and what.

In scope

  • pressbotics.com and the dashboard.
  • The MCP server and the internal publishing rail.
  • Anything crossing the workspace boundary — reading, writing or confirming the existence of another workspace's data.
  • Authentication, session handling and agent key handling.
  • Exposure of stored WordPress credentials in any form.

Out of scope

  • Your own WordPress installation, its plugins and its hosting — report those to the relevant vendor.
  • Denial of service, volumetric or load testing.
  • Social engineering of our team or our users.
  • Reports consisting only of automated scanner output with no demonstrated impact.
  • Missing hardening headers with no exploitable consequence.

What we ask

  • Use your own account and test data. Do not access, modify or retain anyone else's data.
  • Stop at proof of concept — demonstrate the issue, do not exploit it.
  • Give us reasonable time to fix it before disclosing publicly.

What to expect

We acknowledge reports and tell you what we find and what we intend to do. We are a small team and do not run a paid bounty programme, so we will not promise a payout or a fixed response-time SLA we cannot keep. We will credit you if you want the credit.