PandaPinyin Security Policy

Effective date: August 3, 2026

We appreciate responsible reports that help protect PandaPinyin and its users.

Report a vulnerability

Email security reports to hello@pandapinyin.com with “Security report” in the subject line. Include:

Testing guidelines

When investigating a possible vulnerability:

What to expect

We will make a reasonable effort to acknowledge a useful report, investigate it, and communicate material progress. Response time and remediation depend on severity, reproducibility, and operational constraints. PandaPinyin does not currently operate a paid bug-bounty program.

Out of scope

Reports limited to missing best-practice headers, automated scanner output without demonstrated impact, rate-limit observations without a practical abuse case, or issues in unsupported browsers may be treated as informational.