Mirror Security values the security research community and welcomes good-faith reports of vulnerabilities in our products and services. This policy describes how to report vulnerabilities to us, what's in and out of scope, and what to expect after you submit a report.
Submit findings via our vulnerability report page or directly by email to security@mirrorsecurity.io.
For sensitive findings, please encrypt your report using our PGP key:
/security/pgp.txt —
fingerprint 6B74 4F27 BD22 BCF0 7515 57CA 53BA A771 0745 880D.
Include enough detail for our team to reproduce the issue: the affected product, reproduction steps, and the realistic impact.
mirrorsecurity.io,
platform.mirrorsecurity.ioetf.mirrorsecurity.io
To stay within scope and the safe-harbor guarantee in §6, please:
We aim to follow the timelines below. We will engage with you throughout and may adjust based on complexity, third-party dependencies, and active exploitation:
Mirror Security considers research conducted in good faith and in accordance with this policy as authorized. We will not pursue civil action, initiate complaints with law enforcement, or otherwise penalize you for research that complies with this policy.
If a third party (such as a hosting provider, customer, or partner) initiates legal action, we will make a good-faith effort to clarify that your activity was authorized under this policy.
This safe harbor does not authorize you to violate the rules in §4 or applicable laws.
At present we do not have an active compensation program, but when we prepare to launch our bug bounty program we'd be happy to discuss potential collaboration opportunities with you.
With your consent, we'd love to credit researchers who report valid issues in our security advisories or a public hall-of-fame page. Indicate in your report whether you want to be credited and how (real name, handle, or anonymous).
We may update this policy from time to time. The current version is always available at mirrorsecurity.io/security/policy. The "Last updated" date below reflects the most recent change. Material changes are effective on publication and will not retroactively penalize prior good-faith research.