Responsible Disclosure Policy
Overview
MHLE is committed to working with the security community to identify and responsibly fix vulnerabilities in our products and infrastructure. We value the contributions of independent security researchers who help us protect our users.
This policy describes how to report vulnerabilities, what to expect from MHLE during the disclosure process, and what activities are and are not in scope.
How to Report a Vulnerability
Send your report to security@mhle.com with the subject line: [Responsible Disclosure] — <brief description>
What to include
- A clear description of the vulnerability and the potential impact.
- Steps to reproduce the issue (proof-of-concept code, screenshots, or logs are helpful).
- The affected URL, endpoint, or system component.
- Any conditions required to trigger the vulnerability (e.g. authenticated vs. unauthenticated).
We acknowledge all reports within 2 business days and aim to provide a resolution timeline within 10 business days of initial triage.
Our Commitments
When you report a vulnerability in good faith and in accordance with this policy, MHLE will:
- Acknowledge your report promptly and keep you informed of our progress.
- Work collaboratively with you to understand and validate the issue.
- Remediate confirmed vulnerabilities in a timeline proportional to severity.
- Coordinate disclosure with you before any public announcement if you wish.
- Not pursue legal action against you for good-faith research conducted under this policy.
We do not currently offer a paid bug bounty program. We do recognize researchers by name in our security acknowledgements (with your permission).
Scope
In scope
- All production services reachable at
mhle.comand its subdomains. - Authentication and authorization mechanisms (login, session, OAuth, API keys).
- Data exposure and injection vulnerabilities.
- Insecure direct object references and access-control bypasses.
- Server-side request forgery (SSRF).
- Cryptographic weaknesses in data transit or storage.
Out of scope
The following are not eligible for responsible disclosure:
- Denial-of-service attacks or resource exhaustion.
- Social engineering or phishing of MHLE employees.
- Physical security testing.
- Attacks requiring ownership of the victim's device or account.
- Brute-force credential stuffing that does not exploit a systemic flaw.
- Vulnerabilities in third-party services outside our control.
- Security issues in outdated browsers not in our supported matrix.
- Best-practice recommendations without a demonstrated exploit path.
Rules of Engagement
To qualify for good-faith safe-harbor protection:
- Do not access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability.
- Do not disclose the vulnerability to any third party before we have had a reasonable opportunity to remediate it.
- Do not use automated scanners against production systems at a rate that degrades service for other users.
- Do not use the research to gain access to production user data.
- Conduct all testing against accounts you own or have explicit permission to use.
Severity & Response SLA
| Severity | Definition | Target Remediation |
|---|---|---|
| Critical | Remote code execution, mass data exposure, auth bypass | 7 days |
| High | Privilege escalation, significant data exposure | 30 days |
| Medium | Limited data exposure, CSRF, stored XSS | 60 days |
| Low | Information disclosure, best-practice gaps | 90 days |
We may adjust timelines after discussing specifics with the reporter.
Disclosure Timeline
We follow a coordinated disclosure model. MHLE asks that you:
- Provide us at least 30 days from initial report before any public disclosure.
- Contact us before disclosing if you believe we are not making adequate progress.
We will notify you when the vulnerability is fixed and agree on a coordinated disclosure date if you wish to publish a write-up.
Contact
| Channel | Address |
|---|---|
| Security reports | security@mhle.com |
| Privacy inquiries | privacy@mhle.com |
| General contact | hello@mhle.com |
For PGP-encrypted submissions, contact security@mhle.com to request our public key.
Legal
This policy is not a waiver of any legal right MHLE may have. Safe harbor is conditioned on compliance with the rules above. MHLE reserves the right to update this policy at any time.