Personalización

Ajusta tu experiencia

Security policy and vulnerability disclosure

Last updated date: September 2026

At MGPanel we take the security of the platform and of the sites it hosts seriously. This page describes how to report a vulnerability to us, what we do when we receive one, and the terms under which we work with whoever reports it.

This policy is addressed to security researchers and to anyone who finds a flaw. You do not need an account or a commercial relationship with us in order to report.

1. How to report

Send your report to [email protected], starting the subject line with the word "security" so that the message is routed to the technical team.

  • No prior arrangement is required: you may send the full report in your first email.
  • If you prefer to encrypt the message, say so and we will arrange the key exchange.
  • We handle reports in Spanish and English.

This is the only address we monitor for security matters. A report sent through other channels (site forms, social media or sales contacts) may take time to reach the right team.

2. What to include in the report

To validate and fix a finding we need, at a minimum:

  • The affected domain, URL or endpoint.
  • The type of vulnerability and the impact you estimate.
  • Concrete steps to reproduce it, with whatever requests or screenshots are needed.
  • The approximate date and time of your testing, and the IP address you tested from, so we can locate it in our logs.

A report without enough technical information to reproduce the problem cannot be validated and will not be processed. We do not make the review of a report conditional on any prior agreement, and we do not accept reports whose content is offered in exchange for consideration.

3. Scope

The following are within the scope of this policy:

  • The mgpanel.co site and its subdomains.
  • The administration panel and the platform REST API.
  • The MCP server and the authentication mechanisms based on access keys (API Keys).
  • The mobile and desktop applications published by MGPanel.
  • Client websites hosted on the platform, only as regards flaws in the platform itself (for example, a flaw allowing access to data belonging to a different account).

4. Out of scope

The following are not considered vulnerabilities for the purposes of this policy and will generally not lead to a fix:

  • Automated scanner output without a demonstrated exploitation.
  • Missing recommended HTTP headers, or SPF, DKIM or DMARC configurations, where no concrete impact is demonstrated.
  • Disclosure of software versions or informational banners.
  • Clickjacking on pages without sensitive actions, and self-XSS.
  • Missing rate limiting without demonstrated impact.
  • User or email enumeration through error messages.
  • Denial of service, volumetric or resource exhaustion attacks.
  • Social engineering, phishing or physical attacks against our staff or our clients.
  • Vulnerabilities requiring a compromised device, an outdated browser version or physical access to the victim's machine.
  • Content, custom code or configuration uploaded by a client to their own site, where it does not depend on a platform flaw.

5. What you can expect from us

  • We acknowledge receipt of the report within a maximum of 5 business days.
  • We tell you whether the finding was reproduced, dismissed, or whether we need more information.
  • We inform you once the fix has been deployed.
  • We will not pursue legal action against anyone acting in good faith under this policy.

Remediation times depend on the severity and complexity of the flaw. We do not set a single deadline for every case, but we will keep the reporter informed for as long as the case remains open.

6. Testing rules

When investigating, we ask that you:

  • Use only your own or test accounts. You may create a free account for this purpose.
  • Do not access, download, modify or retain data that does not belong to you. If you come across third-party data, stop immediately and include it in the report.
  • Do not degrade the service or affect other users.
  • Do not disclose the vulnerability publicly before it is fixed, and coordinate the timing of disclosure with us.

Testing that goes beyond what is strictly necessary to demonstrate the flaw falls outside this policy.

7. Rewards and acknowledgment

MGPanel does not operate a bug bounty programme. We do not offer monetary compensation for vulnerability reports, nor public acknowledgment, and we do not publish thank-you listings or "halls of fame".

We are grateful for reports and treat them seriously, but the collaboration does not carry consideration of any kind. What we do offer is set out in section 8: if you act in accordance with this policy, we will not pursue legal action against you over your research.

We do not entertain requests for payment, fees or "disclosure fees" as a condition for receiving a report. A message making the delivery of technical information conditional on a payment is not processed as a security report.

8. Safe harbour

If you act in good faith, respect the scope and testing rules of this policy, and give us a reasonable period to fix the issue before disclosing it, we will consider your research authorised and will not initiate or support legal action against you over it.

This commitment does not cover deliberate access to third-party data, its extraction or publication, disruption of the service, or any conduct going beyond what is described in this policy.

9. End customer data

If your finding involves personal data belonging to our users' customers, state this explicitly in the report and do not retain any copy. The processing of such data is governed by our Privacy Policy, and we will trigger whatever notification procedure applies under the relevant regulations.

10. security.txt file

This policy is declared in machine-readable form at /.well-known/security.txt, in accordance with RFC 9116. The same file is published on the sites hosted on the platform so that any MGPanel flaw found on them reaches our team directly.

11. Applicable legislation

This policy is governed by the laws of the Republic of Panama.