What to include
Provide the affected hostname or component, a clear description, reproducible steps, potential impact, relevant timestamps and minimal evidence needed to validate the issue.
Safe-harbour expectations
Research must be conducted in good faith, within the law, using only accounts and data you own or are explicitly authorized to test. Avoid privacy violations, service disruption, social engineering, denial-of-service activity, destructive actions and persistent access.
Out of scope
Automated scanner output without validation, missing security headers with no demonstrated impact, clickjacking on non-sensitive static pages, rate-limit observations that do not create a practical risk, and issues affecting unsupported third-party software are generally low priority.
Do not test production customer data
MindShield supports security-sensitive backup operations. Never attempt to obtain backup files, encryption material, database contents, credentials or cross-tenant information. Report the observation and stop.
Our process
We aim to acknowledge credible reports, assess severity, request clarification where necessary, coordinate remediation and communicate when an issue can be safely disclosed. Response times may vary by complexity and impact.
No public disclosure before coordination
Please allow reasonable time for investigation and remediation before publishing details. Public disclosure should be coordinated with the security team.
Rewards
A formal bug-bounty or monetary reward programme is not currently promised. Any recognition or reward is discretionary and must not be assumed before testing.
Report securely
Send reports to security@mindshieldpk.com. Do not attach customer data, secrets, malware or large database files. Ask for a secure transfer method if additional evidence is required.
