TesterAgent

Security and responsible disclosure

TesterAgent never sees or stores your passwords, deletes uploaded APKs right after the check and logged-in sessions when the audit ends, and keeps only a one-way hash of visitor IP addresses. Found a vulnerability in TesterAgent? Report it to us; good-faith research under the rules below is welcome and safe.

How we protect your data

  • HTTPS for every page (HSTS); cookies HttpOnly, SameSite=Lax and Secure; every form checked against cross-site requests; a strict Content-Security-Policy.
  • Passwords hashed with scrypt; sign-in tokens and email links stored only as SHA-256 hashes; a password reset signs out every session.
  • Reports contain text from tested sites, so they are served sandboxed in a separate origin; screenshot addresses contain a random part; every id is a random UUID.
  • Logged-in testing: you type into a live view of our browser; keystrokes are forwarded and never logged; the session file (owner-only permissions) is deleted when the audit ends.
  • Our test browsers refuse private, internal and cloud-metadata addresses; the live-view port of the worker is never public.
  • Secrets live only in server environment variables, never in code or logs. Retention: Data retention policy; providers: Sub-processors.

Report a vulnerability

Email [[OWNER: security email (SECURITY_EMAIL)]] / the Contact page with the affected URL, the steps to reproduce, the impact you see and your contact details. Please write in English, Lao or Thai. We acknowledge reports within 5 working days and tell you when the issue is fixed. Our security.txt lists the same contact.

Safe harbor

  • If you act in good faith and follow these rules, we will not take legal action against you or ask anyone else to, and we consider your research authorised.
  • Use only your own account(s); never access, change or delete other customers’ data — stop and report as soon as you see any.
  • No denial of service, load or volume testing, spam, social engineering or physical attacks.
  • Do not use TesterAgent’s audit browsers to attack third parties, and do not test our providers (Lemon Squeezy, Cloudinary, MongoDB, Cloudflare) — report issues there to them.
  • Give us reasonable time to fix the issue (90 days unless we agree otherwise) before telling anyone else.

Bug bounty

We have no paid bug-bounty programme yet. With your permission we gladly thank you by name on this page.