Mend.io Responsible Disclosure Policy

At Mend.io, the security and privacy of our users and systems are core priorities. We welcome contributions from the security community and encourage responsible reporting of vulnerabilities. If you’ve discovered a potential security issue in one of our systems, products, or websites, we want to hear from you. We appreciate your help!

How to report a vulnerability:

If you identify a security vulnerability, please report it per the instructions below and include as much detail as possible to help us reproduce and understand the issue, such as:

You may choose to report anonymously, but please note that we may not be able to provide follow-up communication if you do not identify yourself.

For any questions, you may also contact us via email at security@mend.io.

Please Do:

Do Not:

Out of scope vulnerabilities:

The following types of issues are outside the scope of this policy:

What happens next:

Once we receive your report, we will:

Please note: resolution timelines vary depending on the nature of the issue.

Response targets for this program:

Time to first response: 1 day

Time to triage: 2 days

Time to resolution: 45 days

Legal Safe Harbor:

If you comply with this policy, we will not pursue legal action against you for security research activities. However, noncompliance or actions that violate applicable law or our Terms of Service may result in legal consequences. In addition, we make no representation or warranty on behalf of any third-party. Third-party individuals and entities may independently assess whether your actions may have caused harm to such third parties or violated their terms of use and, therefore, may independently seek legal action or remedies.

Thank you for helping us keep our systems, products and websites safe!