Security and responsible reporting.
PrufAgent handles sensitive lookup intent, receipt emails, and digital report access. Security reports and abuse concerns should be sent through the channels below.
Report a vulnerability
Email support@prufagent.com with the subject line "Security report" plus a clear description, affected URL, reproduction steps, and impact. Do not include passwords, payment-card numbers, private keys, or unrelated personal data.
Research boundaries
- Do not access, alter, delete, or exfiltrate data that is not yours.
- Do not run denial-of-service, spam, phishing, social engineering, or destructive tests.
- Use test accounts and safe proof-of-concept evidence whenever possible.
- Stop and report immediately if you encounter private customer data.
Payment and report safety
Payments are processed by Stripe. PrufAgent does not store raw payment-card numbers. Report access is tied to receipt email, account claim state, and Stripe webhook confirmation.
Abuse reports
For harassment, stalking concerns, impersonation, illegal use, or sensitive removal requests, email support@prufagent.com with exact URLs, order context when relevant, and why the request is urgent.
Operational safeguards
- Production traffic is served over HTTPS and application secrets remain in server-side configuration rather than public browser code.
- Authenticated report routes verify account tokens and paid entitlements before returning protected report data.
- Customer evidence responses redact contact-shaped values and remove protected-session implementation details from non-admin reports.
- Checkout fulfillment depends on signed Stripe webhook events instead of trusting a browser redirect alone.
- Application and web-server error logs are reviewed during production changes, with rollback copies retained for deployed files.
Response and disclosure process
Reports are triaged by affected surface, reproducibility, customer impact, and whether credentials or payment fulfillment are involved. A useful report includes the exact endpoint, request sequence, expected behavior, observed behavior, and a minimal proof that avoids collecting unrelated customer data.
PrufAgent does not promise a bounty or fixed response deadline. We will acknowledge actionable reports when possible, investigate evidence in good faith, and prioritize issues that could expose report access, account identity, payment state, or server credentials.