Effective date: August 3, 2026
We appreciate responsible reports that help protect PandaPinyin and its users.
Report a vulnerability
Email security reports to hello@pandapinyin.com with “Security report” in the subject line. Include:
- a clear description of the issue and its impact;
- the affected URL, endpoint, or feature;
- reproduction steps or a minimal proof of concept;
- relevant screenshots, request IDs, or non-sensitive logs;
- a safe way for us to contact you.
Testing guidelines
When investigating a possible vulnerability:
- use only accounts and data you own or have permission to test;
- do not access, modify, retain, or share another user’s data;
- do not perform denial-of-service, spam, or destructive testing;
- do not use social engineering, phishing, or physical attacks;
- stop testing when you confirm that sensitive data is exposed;
- give us a reasonable opportunity to investigate before disclosure.
What to expect
We will make a reasonable effort to acknowledge a useful report, investigate it, and communicate material progress. Response time and remediation depend on severity, reproducibility, and operational constraints. PandaPinyin does not currently operate a paid bug-bounty program.
Out of scope
Reports limited to missing best-practice headers, automated scanner output without demonstrated impact, rate-limit observations without a practical abuse case, or issues in unsupported browsers may be treated as informational.