Customer Assurance Current public

Responsible Disclosure Policy

Version 1.0 Effective August 16, 2026 Last updated August 31, 2026
## Overview

MHLE is committed to working with the security community to identify and responsibly fix
vulnerabilities in our products and infrastructure. We value the contributions of independent
security researchers who help us protect our users.

This policy describes how to report vulnerabilities, what to expect from MHLE during the
disclosure process, and what activities are and are not in scope.

---

## How to Report a Vulnerability

Send your report to **security@mhle.com** with the subject line:
**[Responsible Disclosure] — <brief description>**

### What to include

- A clear description of the vulnerability and the potential impact.
- Steps to reproduce the issue (proof-of-concept code, screenshots, or logs are helpful).
- The affected URL, endpoint, or system component.
- Any conditions required to trigger the vulnerability (e.g. authenticated vs. unauthenticated).

We acknowledge all reports within **2 business days** and aim to provide a resolution
timeline within **10 business days** of initial triage.

---

## Our Commitments

When you report a vulnerability in good faith and in accordance with this policy, MHLE will:

1. **Acknowledge** your report promptly and keep you informed of our progress.
2. **Work collaboratively** with you to understand and validate the issue.
3. **Remediate** confirmed vulnerabilities in a timeline proportional to severity.
4. **Coordinate disclosure** with you before any public announcement if you wish.
5. **Not pursue legal action** against you for good-faith research conducted under this policy.

We do not currently offer a paid bug bounty program. We do recognize researchers by name in
our security acknowledgements (with your permission).

---

## Scope

### In scope

- All production services reachable at `mhle.com` and its subdomains.
- Authentication and authorization mechanisms (login, session, OAuth, API keys).
- Data exposure and injection vulnerabilities.
- Insecure direct object references and access-control bypasses.
- Server-side request forgery (SSRF).
- Cryptographic weaknesses in data transit or storage.

### Out of scope

The following are **not** eligible for responsible disclosure:

- Denial-of-service attacks or resource exhaustion.
- Social engineering or phishing of MHLE employees.
- Physical security testing.
- Attacks requiring ownership of the victim's device or account.
- Brute-force credential stuffing that does not exploit a systemic flaw.
- Vulnerabilities in third-party services outside our control.
- Security issues in outdated browsers not in our supported matrix.
- Best-practice recommendations without a demonstrated exploit path.

---

## Rules of Engagement

To qualify for good-faith safe-harbor protection:

- Do **not** access, modify, or exfiltrate data beyond what is strictly necessary to
  demonstrate the vulnerability.
- Do **not** disclose the vulnerability to any third party before we have had a reasonable
  opportunity to remediate it.
- Do **not** use automated scanners against production systems at a rate that degrades
  service for other users.
- Do **not** use the research to gain access to production user data.
- Conduct all testing against accounts you own or have explicit permission to use.

---

## Severity & Response SLA

| Severity | Definition | Target Remediation |
|----------|------------|--------------------|
| Critical | Remote code execution, mass data exposure, auth bypass | 7 days |
| High | Privilege escalation, significant data exposure | 30 days |
| Medium | Limited data exposure, CSRF, stored XSS | 60 days |
| Low | Information disclosure, best-practice gaps | 90 days |

We may adjust timelines after discussing specifics with the reporter.

---

## Disclosure Timeline

We follow a coordinated disclosure model. MHLE asks that you:

- Provide us at least **30 days** from initial report before any public disclosure.
- Contact us before disclosing if you believe we are not making adequate progress.

We will notify you when the vulnerability is fixed and agree on a coordinated disclosure date
if you wish to publish a write-up.

---

## Contact

| Channel | Address |
|---------|---------|
| Security reports | security@mhle.com |
| Privacy inquiries | privacy@mhle.com |
| General contact | hello@mhle.com |

For PGP-encrypted submissions, contact security@mhle.com to request our public key.

---

## Legal

This policy is not a waiver of any legal right MHLE may have. Safe harbor is conditioned on
compliance with the rules above. MHLE reserves the right to update this policy at any time.
Back to Trust Center