Customer Assurance Current public

Responsible Disclosure Policy

Version 1.0 Effective August 16, 2026 Last updated August 24, 2026

Overview

MHLE is committed to working with the security community to identify and responsibly fix vulnerabilities in our products and infrastructure. We value the contributions of independent security researchers who help us protect our users.

This policy describes how to report vulnerabilities, what to expect from MHLE during the disclosure process, and what activities are and are not in scope.


How to Report a Vulnerability

Send your report to security@mhle.com with the subject line: [Responsible Disclosure] — <brief description>

What to include

  • A clear description of the vulnerability and the potential impact.
  • Steps to reproduce the issue (proof-of-concept code, screenshots, or logs are helpful).
  • The affected URL, endpoint, or system component.
  • Any conditions required to trigger the vulnerability (e.g. authenticated vs. unauthenticated).

We acknowledge all reports within 2 business days and aim to provide a resolution timeline within 10 business days of initial triage.


Our Commitments

When you report a vulnerability in good faith and in accordance with this policy, MHLE will:

  1. Acknowledge your report promptly and keep you informed of our progress.
  2. Work collaboratively with you to understand and validate the issue.
  3. Remediate confirmed vulnerabilities in a timeline proportional to severity.
  4. Coordinate disclosure with you before any public announcement if you wish.
  5. Not pursue legal action against you for good-faith research conducted under this policy.

We do not currently offer a paid bug bounty program. We do recognize researchers by name in our security acknowledgements (with your permission).


Scope

In scope

  • All production services reachable at mhle.com and its subdomains.
  • Authentication and authorization mechanisms (login, session, OAuth, API keys).
  • Data exposure and injection vulnerabilities.
  • Insecure direct object references and access-control bypasses.
  • Server-side request forgery (SSRF).
  • Cryptographic weaknesses in data transit or storage.

Out of scope

The following are not eligible for responsible disclosure:

  • Denial-of-service attacks or resource exhaustion.
  • Social engineering or phishing of MHLE employees.
  • Physical security testing.
  • Attacks requiring ownership of the victim's device or account.
  • Brute-force credential stuffing that does not exploit a systemic flaw.
  • Vulnerabilities in third-party services outside our control.
  • Security issues in outdated browsers not in our supported matrix.
  • Best-practice recommendations without a demonstrated exploit path.

Rules of Engagement

To qualify for good-faith safe-harbor protection:

  • Do not access, modify, or exfiltrate data beyond what is strictly necessary to demonstrate the vulnerability.
  • Do not disclose the vulnerability to any third party before we have had a reasonable opportunity to remediate it.
  • Do not use automated scanners against production systems at a rate that degrades service for other users.
  • Do not use the research to gain access to production user data.
  • Conduct all testing against accounts you own or have explicit permission to use.

Severity & Response SLA

Severity Definition Target Remediation
Critical Remote code execution, mass data exposure, auth bypass 7 days
High Privilege escalation, significant data exposure 30 days
Medium Limited data exposure, CSRF, stored XSS 60 days
Low Information disclosure, best-practice gaps 90 days

We may adjust timelines after discussing specifics with the reporter.


Disclosure Timeline

We follow a coordinated disclosure model. MHLE asks that you:

  • Provide us at least 30 days from initial report before any public disclosure.
  • Contact us before disclosing if you believe we are not making adequate progress.

We will notify you when the vulnerability is fixed and agree on a coordinated disclosure date if you wish to publish a write-up.


Contact

Channel Address
Security reports security@mhle.com
Privacy inquiries privacy@mhle.com
General contact hello@mhle.com

For PGP-encrypted submissions, contact security@mhle.com to request our public key.


Legal

This policy is not a waiver of any legal right MHLE may have. Safe harbor is conditioned on compliance with the rules above. MHLE reserves the right to update this policy at any time.

Back to Trust Center