Security reporting
PGH Attorneys welcomes responsible reports of suspected security vulnerabilities affecting pgh.africa, the client portal, public forms, document workflows, authentication, payment routing, or related operating systems.
Send security reports to security@pgh.africa. Include a clear description, affected URL or system, reproduction steps, expected impact, and your contact details. Do not include client matter information, FICA information, privileged material, identity documents, banking details, or other personal information unless PGH Attorneys asks for it through a secure channel.
Do not use testing methods that disrupt service, access or alter data that is not yours, attempt persistence, bypass authentication on accounts you do not control, exploit social engineering, or run destructive scans. Reports must be made in good faith and must comply with applicable law.
PGH Attorneys will review reports, triage risk, preserve evidence where required, and respond through the security contact where a response is appropriate. This page does not create a bug bounty, reward programme, safe-harbour undertaking, service-level agreement, mandate, or attorney-client relationship.
Security incidents involving your own client account or matter must also be reported through the normal client support channel at office@pgh.africa so that identity, mandate, and confidentiality controls can be followed.