Security and responsible disclosure
TesterAgent never sees or stores your passwords, deletes uploaded APKs right after the check and logged-in sessions when the audit ends, and keeps only a one-way hash of visitor IP addresses. Found a vulnerability in TesterAgent? Report it to us; good-faith research under the rules below is welcome and safe.
How we protect your data
- HTTPS for every page (HSTS); cookies HttpOnly, SameSite=Lax and Secure; every form checked against cross-site requests; a strict Content-Security-Policy.
- Passwords hashed with scrypt; sign-in tokens and email links stored only as SHA-256 hashes; a password reset signs out every session.
- Reports contain text from tested sites, so they are served sandboxed in a separate origin; screenshot addresses contain a random part; every id is a random UUID.
- Logged-in testing: you type into a live view of our browser; keystrokes are forwarded and never logged; the session file (owner-only permissions) is deleted when the audit ends.
- Our test browsers refuse private, internal and cloud-metadata addresses; the live-view port of the worker is never public.
- Secrets live only in server environment variables, never in code or logs. Retention: Data retention policy; providers: Sub-processors.
Report a vulnerability
Email [[OWNER: security email (SECURITY_EMAIL)]] / the Contact page with the affected URL, the steps to reproduce, the impact you see and your contact details. Please write in English, Lao or Thai. We acknowledge reports within 5 working days and tell you when the issue is fixed. Our security.txt lists the same contact.
Safe harbor
- If you act in good faith and follow these rules, we will not take legal action against you or ask anyone else to, and we consider your research authorised.
- Use only your own account(s); never access, change or delete other customers’ data — stop and report as soon as you see any.
- No denial of service, load or volume testing, spam, social engineering or physical attacks.
- Do not use TesterAgent’s audit browsers to attack third parties, and do not test our providers (Lemon Squeezy, Cloudinary, MongoDB, Cloudflare) — report issues there to them.
- Give us reasonable time to fix the issue (90 days unless we agree otherwise) before telling anyone else.
Bug bounty
We have no paid bug-bounty programme yet. With your permission we gladly thank you by name on this page.