Responsible disclosure
Report a security issue
Please report suspected vulnerabilities privately so we can investigate them without putting visitors or customer data at risk.
How to report
Email info@pandacodegen.com with the subject Security report. Include the affected URL or component, minimal reproduction steps, expected and observed behavior, and the potential impact.
Use test data and the minimum activity needed to demonstrate the issue. Do not include credentials, personal data, destructive payloads, or details in a public issue.
Scope and response
The public website and its first-party API routes are in scope. Third-party services follow their own disclosure programs. Social engineering, denial-of-service testing, traffic that degrades the service, and accessing another person's data are out of scope.
Reports are triaged by severity and reproducibility. We use provided contact details for material updates, but this public policy does not promise a fixed response or remediation deadline.