Reporting a vulnerability
Email hello@myndstack.io with the subject line "Security". Include the affected endpoint, reproduction steps, and any proof-of-concept. We aim to acknowledge within one business day and to give you a remediation timeline within five.
Please give us a reasonable window to fix an issue before disclosing it publicly. We will not pursue legal action against researchers who report in good faith, act within the scope of their own accounts, avoid privacy violations and service degradation, and do not exfiltrate data.
Out of scope
Reports generated solely by automated scanners without a demonstrated impact, missing best-practice headers with no exploit path, social engineering of our staff, and denial-of-service testing are all out of scope.
How we build
Least-privilege access, credentials in a managed secret store rather than in code, encryption in transit and at rest, dependency and container scanning in CI, and infrastructure defined as code and peer-reviewed before it lands.
Access control
Engineer access to client environments is granted per engagement, requires multi-factor authentication, is logged, and is revoked when the engagement ends. Production access is time-bound and audited.
Data residency
Region-pinned deployment is available where an engagement requires data to stay in a jurisdiction. Residency commitments are recorded in the data processing agreement, not assumed.
Incidents
We notify affected clients without undue delay after confirming an incident that touches their data, with what we know, what we are doing, and what we need from them. A written post-incident review follows.
Compliance
Enterprise security and compliance requirements are scoped per engagement. Ask us for our current posture, subprocessor list, and any certifications relevant to your programme.
Questions about this page? Get in touch.