Security & Responsible Disclosure
We take the security of our products and our customers' data seriously. If you believe you have found a vulnerability in fanpino.com or any Fanpino product, we want to hear from you.
How to report
- Email [email protected] with the subject line starting with "Security:".
- Include the affected URL or product, steps to reproduce, and the impact you observed.
- Give us a reasonable amount of time to fix the issue before disclosing it publicly.
Please don't
- Access, change, or delete data that doesn't belong to you.
- Run denial-of-service, spam, or social engineering attacks against us or our customers.
- Use automated scanners that generate heavy traffic.
What we promise
- We will reply to every good-faith report and keep you updated until it is resolved.
- We will not take legal action against research done in good faith under this policy.
- We will credit you publicly on this page, with your permission.
We don't run a paid bug bounty program. We do recognise every valid report here and are happy to provide a written letter of appreciation.
Hall of Fame
Thank you to these researchers for responsibly reporting issues that made our products safer.
- Dhruv 2026-09
Stored XSS through PDF attachments uploaded to customer support tickets