Skip to content
PATHBREAK Back to home

Security Policy & Vulnerability Disclosure

Last updated: June 9, 2026

Pathbreak builds security tooling, and we hold our own platform to the same standard we expect of others. We welcome reports from security researchers who help us keep our customers and infrastructure safe. This page explains how to report a vulnerability and what you can expect from us in return. It complements our machine-readable /.well-known/security.txt file.

How to report

Please send vulnerability reports to:

  • Email: [email protected]
  • Web: pathbreak.io contact form

To help us triage quickly, include where you can:

  • A clear description of the issue and its potential impact.
  • Step-by-step instructions to reproduce it (proof-of-concept, request and response, or screenshots).
  • The affected URL, endpoint, or component, and the time of testing.
  • Any accounts or test data you used. Do not use other people's accounts.

Scope

In scope

  • pathbreak.io and the subdomains we operate.
  • Our web application, APIs, and authentication flows.

Out of scope

  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Denial-of-service, volumetric, or brute-force testing.
  • Social engineering, phishing, or physical attacks against staff or customers.
  • Third-party services and SaaS we do not control.
  • Any customer cloud environment. Pathbreak only assesses environments with the customer's explicit authorization; please do not test against customer tenants.

Rules of engagement

  • Only test against your own account and data; never access, modify, or destroy data that is not yours.
  • Stop testing and report immediately if you encounter personal data belonging to others.
  • Do not run attacks that degrade availability or performance for other users.
  • Give us a reasonable time to investigate and remediate before any public disclosure.

Our commitment

  • We will acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and work toward a fix.
  • We will not pursue legal action against researchers who act in good faith and follow this policy.
  • With your permission, we are happy to credit you once the issue is resolved.

Preferred languages

We accept reports in English.

Questions about this policy? Contact [email protected].

PATHBREAK

Agentic cloud security. Discover the real attack paths, then break them.

Platform

Overview Attack paths How it works

Company

About Contact [email protected]

Registered office

60 High Street
Wimbledon
London, England
SW19 5EE

Pathbreak Ltd · Company No. 17265710
© 2026 Pathbreak Ltd. All rights reserved.
Terms Privacy Security Trust
Break the path.