Third Party Index

Snapshot 24589

Document
Security advisories
URL
https://docs.perfectwiki.com/Vulnerability-Disclosure_BWdX5DHV7GRhfxFjXlrm
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
198893 bytes
SHA-256 (raw)
7befc2d4bb724d6e093e4e44a9f90699d76a5e6c94f0abc7856e219b4df6b2c5
SHA-256 (normalized text)
8f97198445a1af8a7e2a46cae0fa04765cb3da37918ffb4382cd86975553c222

Normalized text

Scripts and page chrome removed; this is what change detection compares.

👋 Quick Start Guide
🗞️ What's New (Changelog)
⁉️ Frequently Asked Questions
🤖 Knowledge Bot
🔑 Having Trouble Signing In?
📝 What is a Page?
📳 What is a Knowledge Base?
💱 Pricing Structure: how much does it cost?
💸 Billing
🛡️ Trust Center
Information Security Policy
Access Control & Identity Management Policy
Cryptography & Key Management Policy
Data Classification, Retention & Deletion Policy
Incident Response Plan
Business Continuity & Disaster Recovery Plan
Change & Configuration Management Policy
Vulnerability & Patch Management Policy
Vendor & Sub-processor Management Policy
Risk Management Policy
Human Resources Security Policy
Secure Software Development Lifecycle (SDLC) Policy
Asset Management Policy
Logging & Monitoring Policy
Acceptable Use Policy
Sub-processors
Data Processing Agreement (DPA)
Vulnerability Disclosure
⚙️ Account Settings
🧩 Integrations
💟 About Us
Vulnerability Disclosure
Verified
Updated over a week ago
•
2 min read
Perfect Wiki appreciates the work of the security community in keeping our customers safe. If you believe you've found a security vulnerability in our service, we want to hear from you.
How to report
Email: [email protected]
Use a clear subject line, e.g. "Security report: <short summary>".
Include enough detail to reproduce: URL/endpoint, request payload, steps to reproduce, expected vs. actual behavior, impact, and screenshots or video where helpful.
If possible, include suggested mitigation.
If you discovered the issue with an automated tool, please reduce noise by validating the finding manually before submitting.
What we commit to
Acknowledge receipt of your report within 3 business days.
Provide an initial assessment of the report within 10 business days.
Keep you informed of remediation progress.
Credit you in this page or in our changelog if you wish, once the issue is fixed.
Not pursue legal action against researchers who follow the rules below in good faith.
We're small company thus we do NOT have bug bounty program.
Rules of engagement (safe harbor)
We consider research activities that comply with this policy to be authorized, and will not initiate legal action against you for them. To stay within scope:
Do test only against your own account or accounts you have explicit permission to test.
Do not access, modify, or exfiltrate data that does not belong to you.
Do not perform denial-of-service testing, sustained automated scanning, or brute-force attacks.
Do not social-engineer Perfect Wiki personnel, customers, or vendors.
Do not publicly disclose the vulnerability until we confirm it is fixed and we have agreed on a disclosure timeline.
Do stop testing and contact us if you encounter customer data; do not download or retain it.
Scope
In scope:
perfectwiki.com, app.perfectwiki.xyz, api.perfectwiki.xyz, read.perfectwiki.xyz, docs.perfectwiki.com and other Perfect Wiki-operated domains.
The Public API, MCP server, and embedded integrations (Microsoft Teams, Slack).
Out of scope:
Vulnerabilities only exploitable by social engineering or physical access.
Click hijacking, Self-XSS or other issues requiring victim cooperation against their own account with no realistic threat path.
Missing security headers without a demonstrable exploit.
Reports based purely on automated-tool output without a working proof of concept.
Issues in third-party sub-processors that are not specific to Perfect Wiki's configuration.
Rewards
Perfect Wiki does not currently operate a paid bug bounty program. We offer recognition and, at our discretion, swag or credit for genuinely impactful findings.
security.txt
A security.txt file is published at /.well-known/security.txt per RFC 9116.
Related Articles
Asset Management Policy
Logging & Monitoring Policy
Acceptable Use Policy
Sub-processors
Data Processing Agreement (DPA)
Was this page helpful?
Table of Content
How to report
What we commit to
Rules of engagement (safe harbor)
Scope
Rewards
security.txt