Security
Responsible vulnerability disclosure.
If you believe you found a vulnerability in BreakTest, the customer portal, license API, or breaktest.io, email [email protected] with “Security report” in the subject. Include the affected URL or component, impact, reproducible steps, and supporting evidence. Do not include personal data you do not need to share.
Safe-harbor expectations
- Act in good faith and avoid privacy violations, disruption, denial of service, social engineering, spam, and destructive testing.
- Use only accounts and data you own or are explicitly authorized to test.
- Stop once you have enough evidence and give us reasonable time to investigate before public disclosure.
- Do not demand payment or threaten disclosure. We do not currently operate a paid bug-bounty program.
What to expect
We aim to acknowledge a useful report within five business days, keep you informed of material progress, and coordinate disclosure when appropriate. Timelines depend on severity and complexity. Good-faith research that follows this policy will not be pursued by Breaking IT solely because it identified a vulnerability.
Machine-readable policy
Security tools can use /.well-known/security.txt.