Contact
Email hello@pagerook.com with “Security report” in the subject. Include the affected URL or component, impact, reproducible steps, and the least sensitive proof needed. PageRook does not currently publish a PGP key, so do not email live credentials, private keys, full customer datasets, or executable payloads.
View security.txtResponsible testing
- Use accounts, sites, and data you own or have explicit permission to test.
- Stop if testing could expose another person's data, disrupt service, or change a public site you do not control.
- Do not use social engineering, denial of service, physical attacks, malware, automated mass scanning, or persistence.
- Minimise access and retention, explain any accidental exposure immediately, and securely delete copied data after coordination.
- Do not publicly disclose an unresolved issue before PageRook has had a reasonable opportunity to investigate and mitigate it.
What to expect
Reports receive an opaque reference when accepted into the trust and safety process. PageRook will prioritise by risk, may ask for clarification, and will share remediation status when it is safe and lawful to do so. PageRook currently has no public bug-bounty programme and makes no promise of payment. Good-faith reporting does not authorise unlawful access or activity outside these guidelines.
If your PageRook account may be compromised
Revoke affected MCP/OAuth authorisations and client credentials from account settings, avoid publishing new content, and contact hello@pagerook.com. For phishing, malware, or abuse hosted on a PageRook site, use the abuse-reporting instructions in the Acceptable use policy.