Responsible Disclosure
Found something? We would much rather hear it from you than read about it later.
Placeholder — pending legal review
This page sets out the structure and intent of the final document. It is not yet a binding legal text. Replace the sections below with counsel-approved wording before launch.
How to report
Email security@medalock.app with:
- A description of the issue and its potential impact
- Clear reproduction steps, including affected URLs or endpoints
- Any proof-of-concept material you can share safely
- How you would like to be credited, if at all
Please do
- Give us a reasonable window to investigate and fix before publishing
- Test only against your own accounts and data
- Report promptly once you find something
Please do not
- Access, modify or delete data belonging to anyone else
- Degrade the service — no load testing, no denial of service
- Use social engineering, physical intrusion, or spam against our team or our customers
What the final policy will add
- Acknowledgement and response timelines
- Scope: which domains, apps and endpoints are in and out of scope
- Safe-harbour commitments for good-faith research
- Whether a bounty or recognition programme is offered
- A PGP key for encrypted reports
Until then, Medalock commits to reading every report sent to the address above and replying to the researcher who sent it.
