Skip to content

Security & Responsible Disclosure

We take the security of our products and our customers' data seriously. If you believe you have found a vulnerability in fanpino.com or any Fanpino product, we want to hear from you.

How to report

  • Email [email protected] with the subject line starting with "Security:".
  • Include the affected URL or product, steps to reproduce, and the impact you observed.
  • Give us a reasonable amount of time to fix the issue before disclosing it publicly.

Please don't

  • Access, change, or delete data that doesn't belong to you.
  • Run denial-of-service, spam, or social engineering attacks against us or our customers.
  • Use automated scanners that generate heavy traffic.

What we promise

  • We will reply to every good-faith report and keep you updated until it is resolved.
  • We will not take legal action against research done in good faith under this policy.
  • We will credit you publicly on this page, with your permission.

We don't run a paid bug bounty program. We do recognise every valid report here and are happy to provide a written letter of appreciation.

Hall of Fame

Thank you to these researchers for responsibly reporting issues that made our products safer.

  • Dhruv 2026-09

    Stored XSS through PDF attachments uploaded to customer support tickets