Responsible disclosure
Found something? Here is how to tell us.
If you have found a security issue, we want to hear about it. Email info@pressbotics.com with "Security" in the subject. Please report privately first rather than publishing.
What to include
- What the issue is, and the impact you believe it has.
- Steps to reproduce, precise enough for us to follow.
- The affected URL or endpoint, and roughly when you tested.
- Whether you accessed any data that was not yours, and what.
In scope
- pressbotics.com and the dashboard.
- The MCP server and the internal publishing rail.
- Anything crossing the workspace boundary — reading, writing or confirming the existence of another workspace's data.
- Authentication, session handling and agent key handling.
- Exposure of stored WordPress credentials in any form.
Out of scope
- Your own WordPress installation, its plugins and its hosting — report those to the relevant vendor.
- Denial of service, volumetric or load testing.
- Social engineering of our team or our users.
- Reports consisting only of automated scanner output with no demonstrated impact.
- Missing hardening headers with no exploitable consequence.
What we ask
- Use your own account and test data. Do not access, modify or retain anyone else's data.
- Stop at proof of concept — demonstrate the issue, do not exploit it.
- Give us reasonable time to fix it before disclosing publicly.
What to expect
We acknowledge reports and tell you what we find and what we intend to do. We are a small team and do not run a paid bounty programme, so we will not promise a payout or a fixed response-time SLA we cannot keep. We will credit you if you want the credit.

