Security & Trust
Vulnerability Disclosure Policy
Last updated: June 15, 2026
Production Central values the security community. This policy explains how to report security vulnerabilities in the Production Central Service and what you can expect from us. It complements our Security page.
1. Scope
In scope: productioncentral.org and the Production Central application and APIs. Out of scope: third-party services we do not control, denial-of-service testing, social-engineering or physical attacks, and findings from automated scanners without a demonstrated impact.
2. How to report
Email [email protected] with a clear description, the steps to reproduce, affected URLs or endpoints, and any proof-of-concept. Please do not publicly disclose the issue until we have had a reasonable opportunity to remediate it.
3. Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, will work with you to understand and resolve the issue quickly, and will not pursue legal action against you.
4. Guidelines
- Only test against accounts you own or have explicit permission to test.
- Do not access, modify, or delete other users' data.
- Avoid privacy violations, service disruption, and data destruction.
- Give us reasonable time to remediate before disclosure.
5. Our commitment
We will acknowledge your report, keep you informed of our progress, and credit you (with your permission) once the issue is resolved. We do not currently operate a paid bug-bounty program, but we genuinely appreciate responsible disclosure.
More legal documents