Vulnerability disclosure
If you have found a vulnerability in software we operate or in a platform we license, report it to the address above. We acknowledge within two business days and will keep you informed until it is resolved.
- Report to
- security@mlgblockchain.com
- Acknowledgement
- Within two business days
- Disclosure
- Timeline agreed, not imposed
- Bounty
- None currently
What we commit to
- We will not pursue legal action against a researcher acting in good faith under this policy.
- We will agree a disclosure timeline with you rather than impose one.
- We will credit you when the issue is resolved, unless you ask us not to.
Scope
In scope
- Software licensed from the platform catalogue, in any deployment we operate.
- This website and the enquiry handling behind it.
- Client deployments are the client’s to disclose. If a report concerns one, tell us and we will route it without acting on the client’s behalf.
Out of scope
- Findings that require a compromised device or a privileged internal account to reproduce.
- Volumetric denial of service.
- Reports produced solely by an automated scanner with no demonstrated impact.
On bounties
The practice does not currently run a paid bounty programme. Stated rather than implied.