Ajusta tu experiencia
You can log in with:
Or with your e-mail
Be among the first to try the new version of MGPanel, a simpler way to create websites with integrated CRM.
Already have an account? Log inLast updated date: September 2026
At MGPanel we take the security of the platform and of the sites it hosts seriously. This page describes how to report a vulnerability to us, what we do when we receive one, and the terms under which we work with whoever reports it.
This policy is addressed to security researchers and to anyone who finds a flaw. You do not need an account or a commercial relationship with us in order to report.
Send your report to [email protected], starting the subject line with the word "security" so that the message is routed to the technical team.
This is the only address we monitor for security matters. A report sent through other channels (site forms, social media or sales contacts) may take time to reach the right team.
To validate and fix a finding we need, at a minimum:
A report without enough technical information to reproduce the problem cannot be validated and will not be processed. We do not make the review of a report conditional on any prior agreement, and we do not accept reports whose content is offered in exchange for consideration.
The following are within the scope of this policy:
The following are not considered vulnerabilities for the purposes of this policy and will generally not lead to a fix:
Remediation times depend on the severity and complexity of the flaw. We do not set a single deadline for every case, but we will keep the reporter informed for as long as the case remains open.
When investigating, we ask that you:
Testing that goes beyond what is strictly necessary to demonstrate the flaw falls outside this policy.
MGPanel does not operate a bug bounty programme. We do not offer monetary compensation for vulnerability reports, nor public acknowledgment, and we do not publish thank-you listings or "halls of fame".
We are grateful for reports and treat them seriously, but the collaboration does not carry consideration of any kind. What we do offer is set out in section 8: if you act in accordance with this policy, we will not pursue legal action against you over your research.
We do not entertain requests for payment, fees or "disclosure fees" as a condition for receiving a report. A message making the delivery of technical information conditional on a payment is not processed as a security report.
If you act in good faith, respect the scope and testing rules of this policy, and give us a reasonable period to fix the issue before disclosing it, we will consider your research authorised and will not initiate or support legal action against you over it.
This commitment does not cover deliberate access to third-party data, its extraction or publication, disruption of the service, or any conduct going beyond what is described in this policy.
If your finding involves personal data belonging to our users' customers, state this explicitly in the report and do not retain any copy. The processing of such data is governed by our Privacy Policy, and we will trigger whatever notification procedure applies under the relevant regulations.
This policy is declared in machine-readable form at /.well-known/security.txt, in accordance with RFC 9116. The same file is published on the sites hosted on the platform so that any MGPanel flaw found on them reaches our team directly.
This policy is governed by the laws of the Republic of Panama.