Vulnerability disclosure

Report a suspected vulnerability to security@mainbrella.com. Please report privately before publishing details so we can investigate and coordinate a fix.

What to include

Include the affected URL or feature, a description of the impact, minimal reproduction steps, and a way to contact you. Redact credentials and personal data. Do not send a live API key, SSH token, or another person's information.

Scope and permitted testing

This policy covers Mainbrella-controlled services at mainbrella.com, api.mainbrella.com, and ssh.mainbrella.com. Use your own accounts and containers, low request rates, and the smallest proof needed to demonstrate an issue. Ask us first if a test would cross an account or isolation boundary.

Third-party services, including Cloudflare's platform, Google, and Stripe, are outside this authorization. Follow those providers' own reporting policies for issues in their systems.

Prohibited testing

Do not access or modify other users' data, persist access, deploy malware, exfiltrate secrets, attempt an actual sandbox escape, disrupt service, run denial-of-service or load tests, bypass payments to obtain compute, or use phishing or social engineering. Do not test systems you do not control.

If you encounter someone else's data unexpectedly, stop immediately, retain only the minimum redacted evidence, and notify us. Do not explore further.

Good-faith reports

Mainbrella authorizes research that follows this policy and will not treat that research or a good-faith report as abuse, or initiate legal action against you for that authorized activity. This commitment applies to Mainbrella; it cannot authorize access to a third party or waive its rights.

We will review reports, follow up when more information is needed, and coordinate disclosure with the reporter. No bounty or guaranteed response time is offered. If you need an update, reply to your original report.