Customer Assurance
Current
public
Responsible Disclosure Policy
Version 1.0
Effective August 16, 2026
Last updated August 31, 2026
## Overview MHLE is committed to working with the security community to identify and responsibly fix vulnerabilities in our products and infrastructure. We value the contributions of independent security researchers who help us protect our users. This policy describes how to report vulnerabilities, what to expect from MHLE during the disclosure process, and what activities are and are not in scope. --- ## How to Report a Vulnerability Send your report to **security@mhle.com** with the subject line: **[Responsible Disclosure] — <brief description>** ### What to include - A clear description of the vulnerability and the potential impact. - Steps to reproduce the issue (proof-of-concept code, screenshots, or logs are helpful). - The affected URL, endpoint, or system component. - Any conditions required to trigger the vulnerability (e.g. authenticated vs. unauthenticated). We acknowledge all reports within **2 business days** and aim to provide a resolution timeline within **10 business days** of initial triage. --- ## Our Commitments When you report a vulnerability in good faith and in accordance with this policy, MHLE will: 1. **Acknowledge** your report promptly and keep you informed of our progress. 2. **Work collaboratively** with you to understand and validate the issue. 3. **Remediate** confirmed vulnerabilities in a timeline proportional to severity. 4. **Coordinate disclosure** with you before any public announcement if you wish. 5. **Not pursue legal action** against you for good-faith research conducted under this policy. We do not currently offer a paid bug bounty program. We do recognize researchers by name in our security acknowledgements (with your permission). --- ## Scope ### In scope - All production services reachable at `mhle.com` and its subdomains. - Authentication and authorization mechanisms (login, session, OAuth, API keys). - Data exposure and injection vulnerabilities. - Insecure direct object references and access-control bypasses. - Server-side request forgery (SSRF). - Cryptographic weaknesses in data transit or storage. ### Out of scope The following are **not** eligible for responsible disclosure: - Denial-of-service attacks or resource exhaustion. - Social engineering or phishing of MHLE employees. - Physical security testing. - Attacks requiring ownership of the victim's device or account. - Brute-force credential stuffing that does not exploit a systemic flaw. - Vulnerabilities in third-party services outside our control. - Security issues in outdated browsers not in our supported matrix. - Best-practice recommendations without a demonstrated exploit path. --- ## Rules of Engagement To qualify for good-faith safe-harbor protection: - Do **not** access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability. - Do **not** disclose the vulnerability to any third party before we have had a reasonable opportunity to remediate it. - Do **not** use automated scanners against production systems at a rate that degrades service for other users. - Do **not** use the research to gain access to production user data. - Conduct all testing against accounts you own or have explicit permission to use. --- ## Severity & Response SLA | Severity | Definition | Target Remediation | |----------|------------|--------------------| | Critical | Remote code execution, mass data exposure, auth bypass | 7 days | | High | Privilege escalation, significant data exposure | 30 days | | Medium | Limited data exposure, CSRF, stored XSS | 60 days | | Low | Information disclosure, best-practice gaps | 90 days | We may adjust timelines after discussing specifics with the reporter. --- ## Disclosure Timeline We follow a coordinated disclosure model. MHLE asks that you: - Provide us at least **30 days** from initial report before any public disclosure. - Contact us before disclosing if you believe we are not making adequate progress. We will notify you when the vulnerability is fixed and agree on a coordinated disclosure date if you wish to publish a write-up. --- ## Contact | Channel | Address | |---------|---------| | Security reports | security@mhle.com | | Privacy inquiries | privacy@mhle.com | | General contact | hello@mhle.com | For PGP-encrypted submissions, contact security@mhle.com to request our public key. --- ## Legal This policy is not a waiver of any legal right MHLE may have. Safe harbor is conditioned on compliance with the rules above. MHLE reserves the right to update this policy at any time.