PageWeave

Security

Found something? Tell us.

This is the vulnerability disclosure policy for PageWeave. If you find a security issue in the platform, report it — we read every report, we fix fast, and good-faith research is welcome.

01 — Scope

What this policy covers.

In scope: pageweave.dev (dashboard, API, MCP endpoint), the pageweave.site infrastructure that serves and gates websites, and PageWeave-operated services such as the docs and the showcase.

Out of scope: security issues in a customer website's own content — that site's owner owns its code; contact them directly. Also out of scope: spam, denial-of-service, social engineering, physical attacks, and raw automated scanner output with no actual issue behind it.

02 — Report

One address, always read.

Send your report to security@pageweave.dev. Plain text is fine.

What helps us act fast

  • The affected URL or system, and a short title for the issue.
  • A description with the steps needed to reproduce it.
  • The impact — what could an attacker do with it?
  • A proof of concept, screenshots, or HTTP traces if you have them.

03 — Response

What happens next.

We acknowledge every report within two business days. We confirm the issue, assess the impact, fix it, and keep you updated while the fix is in progress. If the report turns out to be out of scope, we tell you why.

We coordinate disclosure with you before anything is published. If you want public credit for the finding, say so in your report — you get named.

While you research, keep it clean: use only what is needed to confirm the issue, avoid disrupting the service, do not keep or exfiltrate data, and stop and report immediately if you come across sensitive information. Give us time to ship a fix before you publish details.

04 — Safe harbor

Good faith is authorized.

Good-faith research that follows this policy is authorized. We will not pursue legal action over it, will not invoke anti-circumvention law or our own terms against you for research that follows this policy, and will make that authorization known if a third party raises a claim against you.

PageWeave has no bug bounty program. Reports from good-faith research still get the full treatment: read, confirmed, fixed.

Curious how the platform is built? The security architecture — domain isolation, cookie policy, spam protection — is documented in the security docs.

Policy reviewed 2026-09 · security@pageweave.dev