Security
Found a vulnerability in Pikzels? Email it straight to the person who reviews it.
Who reviews reports
Jannis Carstensen, Chief Technology Officer, is responsible for application security at Pikzels. That covers reviewing vulnerability reports & coordinating fixes.
Email: security@pikzels.com
What to include
- 01. The affected URL or endpoint
- 02. Steps to reproduce
- 03. The impact: what someone could do with it
Leave out passwords, API keys, session tokens & anyone's personal information. If you need to show data, use your own account.
Testing boundaries
- Only test websites, apps & APIs run by Pikzels.
- Use accounts you own, or accounts whose owner gave you express permission.
- Don't access, change or delete anyone else's data. If you reach it, stop there.
- Don't disrupt the service: no denial-of-service, load testing or spam.
- Don't test the third-party providers we rely on. Report issues in their services to them.
What Happens Next
We review reports & prioritize fixes based on their impact.
We may offer a reward for confirmed vulnerabilities, depending on severity. Rewards are discretionary & not guaranteed.