Latest update A domain ordered with hosting is checked, priced and registered

Security

PNLCS handles billing, customer credentials and payment integrations for real hosting businesses. A security defect can affect invoices, customer data and payments.

After you report

Please do not open a public issue, discussion or forum thread for a security finding.

What to expect

  1. Within 48 hours

    Acknowledgement

    You hear back that the report arrived.

  2. Within 5 business days

    Triage

    A first assessment and a severity rating.

  3. Weekly

    Status updates

    Sooner for critical issues.

  4. Typically 14 days

    Fix released

    For critical issues, counted from confirmation.

  5. 90 days

    Disclosure

    The default window, negotiable.

In scope

  • The application: admin area, client portal, API, queue workers, scheduled jobs
  • Authentication, roles, sessions and tokens
  • Payment gateway, registrar and server integrations
  • Templates and views in the default themes
  • Install and upgrade scripts published from the repository

Out of scope

  • Attacks needing physical or root-equivalent access
  • Defects in third-party packages (report them upstream)
  • Self-XSS, or missing headers without a real attack path
  • Automated scanner output with no demonstrated impact
  • The demo and sandbox instances run by Panelica
  • Forks and modified copies

Built-in protections

What PNLCS does to keep an installation safe, and what you should check after installing.

Security checklist
Role-based access
More than 45 fine-grained permissions for staff.
Two-factor authentication
For staff and clients, with recovery codes for staff.
Rate limiting
Login, 2FA, password reset and email resend.
Activity log
Every admin action is recorded.
Fenced hosting tools
Every file, DNS, cron and backup action is checked against the customer’s own domains.
Guarded provisioning
On Proxmox, PNLCS acts only on machines it created and marked.

We do not run a paid bug bounty, but researchers can be credited in the advisory and changelog. We will not pursue good-faith research that follows the policy.