Skip to content
Medalock
Back to Medalock
Legal

Responsible Disclosure

Found something? We would much rather hear it from you than read about it later.

Placeholder — pending legal review

This page sets out the structure and intent of the final document. It is not yet a binding legal text. Replace the sections below with counsel-approved wording before launch.

How to report

Email security@medalock.app with:

  • A description of the issue and its potential impact
  • Clear reproduction steps, including affected URLs or endpoints
  • Any proof-of-concept material you can share safely
  • How you would like to be credited, if at all

Please do

  • Give us a reasonable window to investigate and fix before publishing
  • Test only against your own accounts and data
  • Report promptly once you find something

Please do not

  • Access, modify or delete data belonging to anyone else
  • Degrade the service — no load testing, no denial of service
  • Use social engineering, physical intrusion, or spam against our team or our customers

What the final policy will add

  • Acknowledgement and response timelines
  • Scope: which domains, apps and endpoints are in and out of scope
  • Safe-harbour commitments for good-faith research
  • Whether a bounty or recognition programme is offered
  • A PGP key for encrypted reports

Until then, Medalock commits to reading every report sent to the address above and replying to the researcher who sent it.

$9/mo per protected platform