Report a vulnerability
How to report a security issue to us, what you may test and what we promise researchers.
If you've found a vulnerability on Prop Hub's sites or API, please tell us — we're grateful to everyone who helps keep the platform safe.
How to report
Email [email protected] with the subject "Security". Include:
- what exactly is vulnerable — the page or API URL, parameter, scenario;
- steps to reproduce the issue;
- what it could lead to;
- how to reach you if we need details.
You can write in English, Russian or Spanish.
What you may test
All sites and APIs on prop-hub.pro and its subdomains: the website, the app, the Help Center, partner dashboards and the API.
How to identify your testing
So we can tell your testing apart from an attack, include in your report:
- the IP addresses you tested from;
- the approximate time of testing (with time zone);
- the email addresses of the accounts you used for testing.
Register separate accounts for testing and test only on them.
What you must not do
- Access other people's accounts, balances or data — a minimal proof on your own account is enough.
- Withdraw or move real money, or create fake payments.
- Disrupt the service: load attacks, mass requests, spam.
- Social engineering against staff or users, or physical access.
- Publish details of the vulnerability before we've fixed it.
What we promise
- We'll reply to your report and keep you updated on the fix.
- We won't take action against good-faith research within these rules.
- We'll let you know when the issue is fixed and, if you like, credit you for the finding.
We believe security research matters and should always be rewarded: we thank the author of every confirmed finding. The reward depends on the severity of the vulnerability and is agreed after it's confirmed.
The machine-readable contacts are in security.txt.