Security
Last updated
If you have found a vulnerability in something of ours, we want to hear about it, and the safe harbour below covers you for telling us.
Reporting
Email the address in the footer with SECURITY in the subject. Tell us what you found, where, and enough for us to reproduce it. If you want to encrypt the report, say so and we will arrange a key.
The same address is published in /.well-known/security.txt.
What we commit to
- We acknowledge a report within two business days.
- We tell you whether we consider it a vulnerability, and why, within ten business days.
- We keep you informed while we fix it, and we tell you when it ships.
- We credit you by name if you want the credit, and stay quiet otherwise.
Safe harbour
If you make a good-faith effort to follow this page, we will not pursue or support legal action against you for your research, and we will say so to anyone who asks. Good faith means: stop at proof of concept, do not access or modify data that is not yours, do not degrade the service for anyone else, and give us a reasonable chance to fix it before you publish.
In scope
miranium.aiand its subdomains.- Our products, where you are testing an instance you are entitled to use.
Out of scope
Reports of these are usually closed as informational, because they describe a scanner’s opinion rather than something an attacker can use:
- Missing headers or a weak TLS-configuration grade, unless a report demonstrates impact.
- Denial of service, volumetric testing, or anything that degrades the service for other people.
- Social engineering of our staff, our customers, or our suppliers.
- Findings that require physical access to a device, or a browser or operating system that is already compromised.
- Email deliverability opinions — SPF, DKIM and DMARC are published; tell us if you believe one is genuinely wrong.
Credit is the reward
Credit and thanks are the whole reward for a report. We would rather say so than let you spend a weekend expecting a payout. Everything above is a commitment regardless.