Report a vulnerability
Responsible disclosure · Pantherfield sites
If you notice a security weakness in a Pantherfield website or form, tell us privately. Stop at the first sign of an issue. Please do not access other people’s data or interrupt the service.
How to report
Email contact@pantherfield.com with the subject "Security report". Include the affected URL, what you observed, when you noticed it, why you think it matters and a safe way to reach you. Describe steps without running further tests. We do not have an encrypted vulnerability-upload channel; do not email credentials, customer records, patient data, exploit payloads or copies of personal information.
Scope
Reports about pantherfield.com, www.pantherfield.com (if served), pantherfield-staging.pages.dev and their published pages and company enquiry or community application forms are in scope. Third-party infrastructure such as Cloudflare, Turnstile, Resend, social networks, email providers and sites we link to are outside Pantherfield’s authority; report those issues to the provider.
Research boundaries and good faith
We welcome reports made in good faith to help protect users. Do not use social engineering, phishing, brute force, denial of service, automated high-volume scanning, persistence, data exfiltration, or attempts to access another person’s account or data. Do not alter, delete, retain or disclose data. If you encounter personal information unexpectedly, stop, do not copy it, and tell us only the minimum needed to locate the issue.
We will handle good-faith reports constructively within these boundaries. This promise concerns Pantherfield only; it does not bind public authorities or third parties, excuse unlawful conduct or permit intrusive testing or exploitation. If a test might be intrusive, ask first and wait for written permission.
We won't pursue legal action against good-faith security research conducted within these guidelines.
What happens next
We will review reports sent to the contact mailbox, acknowledge receipt when a contact address is supplied, and route actionable issues for assessment. We may ask for clarification and will give an update when there is a material change we can share safely. We cannot promise a fixed fix date, reward, public credit or a response to spam and duplicate reports. Please allow time to investigate before publishing technical details; coordinate disclosure with us.
Reference
This reporting route takes its responsible-reporting shape from GovTech Singapore’s Vulnerability Disclosure Programme; it does not adopt GovTech’s scope, timelines or legal terms. See the source at GovTech vulnerability reporting.