Vulnerability Disclosure Policy

TL;DR: Report security issues to security@mirrorsecurity.io (encrypt with our PGP key for sensitive findings). We acknowledge within 2 business days, triage within 5 business days, and aim to resolve critical issues within 30 days. Acting in good faith under this policy means we will not pursue legal action against you.

1. Introduction

Mirror Security values the security research community and welcomes good-faith reports of vulnerabilities in our products and services. This policy describes how to report vulnerabilities to us, what's in and out of scope, and what to expect after you submit a report.

2. How to report

Submit findings via our vulnerability report page or directly by email to security@mirrorsecurity.io.

For sensitive findings, please encrypt your report using our PGP key: /security/pgp.txt — fingerprint 6B74 4F27 BD22 BCF0 7515 57CA 53BA A771 0745 880D.

Include enough detail for our team to reproduce the issue: the affected product, reproduction steps, and the realistic impact.

3. Scope

3.1 In scope

3.2 Out of scope

4. Rules of engagement

To stay within scope and the safe-harbor guarantee in §6, please:

5. Coordinated disclosure timeline

We aim to follow the timelines below. We will engage with you throughout and may adjust based on complexity, third-party dependencies, and active exploitation:

6. Safe harbor

Mirror Security considers research conducted in good faith and in accordance with this policy as authorized. We will not pursue civil action, initiate complaints with law enforcement, or otherwise penalize you for research that complies with this policy.

If a third party (such as a hosting provider, customer, or partner) initiates legal action, we will make a good-faith effort to clarify that your activity was authorized under this policy.

This safe harbor does not authorize you to violate the rules in §4 or applicable laws.

7. Compensation

At present we do not have an active compensation program, but when we prepare to launch our bug bounty program we'd be happy to discuss potential collaboration opportunities with you.

8. Acknowledgement

With your consent, we'd love to credit researchers who report valid issues in our security advisories or a public hall-of-fame page. Indicate in your report whether you want to be credited and how (real name, handle, or anonymous).

9. Modifications to this policy

We may update this policy from time to time. The current version is always available at mirrorsecurity.io/security/policy. The "Last updated" date below reflects the most recent change. Material changes are effective on publication and will not retroactively penalize prior good-faith research.

Last updated 2026-05-03 · security.txt · Report · PGP key