How to report
Submit a concise description through the contact channel or call 03206689940. Do not include live credentials, private customer data or destructive proof-of-concept material in an initial report.
Include where possible
- Affected product, page, endpoint or version.
- Clear reproduction steps using non-sensitive test data.
- Potential impact and required preconditions.
- Your preferred contact method.
Research boundaries
- Do not access, alter or retain data belonging to others.
- Do not degrade service availability or perform denial-of-service testing.
- Do not use social engineering, physical intrusion or credential attacks.
- Allow reasonable time for investigation and remediation before disclosure.
Response expectations
MindShield aims to acknowledge credible reports promptly, but no fixed remediation or bounty commitment is made on this public page. Timelines depend on severity, reproducibility and affected systems.
