Security
PNLCS handles billing, customer credentials and payment integrations for real hosting businesses. A security defect can affect invoices, customer data and payments.
After you report
Please do not open a public issue, discussion or forum thread for a security finding.
What to expect
Within 48 hours
Acknowledgement
You hear back that the report arrived.
Within 5 business days
Triage
A first assessment and a severity rating.
Weekly
Status updates
Sooner for critical issues.
Typically 14 days
Fix released
For critical issues, counted from confirmation.
90 days
Disclosure
The default window, negotiable.
In scope
- The application: admin area, client portal, API, queue workers, scheduled jobs
- Authentication, roles, sessions and tokens
- Payment gateway, registrar and server integrations
- Templates and views in the default themes
- Install and upgrade scripts published from the repository
Out of scope
- Attacks needing physical or root-equivalent access
- Defects in third-party packages (report them upstream)
- Self-XSS, or missing headers without a real attack path
- Automated scanner output with no demonstrated impact
- The demo and sandbox instances run by Panelica
- Forks and modified copies
Built-in protections
What PNLCS does to keep an installation safe, and what you should check after installing.
- Role-based access
- More than 45 fine-grained permissions for staff.
- Two-factor authentication
- For staff and clients, with recovery codes for staff.
- Rate limiting
- Login, 2FA, password reset and email resend.
- Activity log
- Every admin action is recorded.
- Fenced hosting tools
- Every file, DNS, cron and backup action is checked against the customer’s own domains.
- Guarded provisioning
- On Proxmox, PNLCS acts only on machines it created and marked.
We do not run a paid bug bounty, but researchers can be credited in the advisory and changelog. We will not pursue good-faith research that follows the policy.