Security Disclosure Policy

Effective Date: 01-01-2025

1. Purpose

At mediabirdco.net, we prioritize the security and integrity of our infrastructure and client data. This Security Disclosure Policy outlines our commitment to security and encourages responsible disclosure of potential vulnerabilities found in our systems.

2. Scope

This policy applies to all digital assets owned or operated by mediabirdco.net, including but not limited to our hosting platform, control panels, APIs, websites, client portals, and support systems.

3. Responsible Disclosure Guidelines

We welcome reports from independent security researchers and the community. If you believe you’ve discovered a security issue, we encourage you to share it with us responsibly by adhering to the following:

  • Provide a detailed description of the vulnerability, including steps to reproduce the issue.
  • Avoid exploiting or abusing the vulnerability beyond what is necessary to demonstrate the issue.
  • Do not publicly disclose the issue until we’ve had a reasonable opportunity to resolve it.
  • Only use your own accounts and data during testing, or secure written permission for limited testing.

4. What You Can Expect From Us

  • We will acknowledge receipt of your report within 3 business days.
  • We will investigate and validate the issue promptly.
  • If confirmed, we will work to resolve the issue in a timely manner.
  • We will credit your responsible disclosure (if desired and legally allowed).

5. Out of Scope

Some findings may not qualify under this policy, including but not limited to:

  • Social engineering or phishing attacks on our staff or users.
  • Denial-of-Service (DoS) attacks or brute-force testing.
  • Reports of outdated software versions without a demonstrable vulnerability.
  • Missing HTTP security headers without impact.
  • Issues requiring physical access to our systems or infrastructure.

6. Reporting a Vulnerability

Please send your findings to our security team via the following secure contact methods:

  • Email: security@mediabirdco.net
  • Subject Line: Security Vulnerability Disclosure
  • Include your name, contact info, and full details of the suspected vulnerability.

7. Legal Safe Harbor

We will not initiate legal action against individuals who submit vulnerabilities in good faith and comply with this policy. Any activities conducted under this policy must be limited to testing systems you own or have explicit permission to test.

8. Responsibilities

  • mediabirdco.net: Maintain transparent and efficient processes for addressing security issues.
  • Security Researchers: Act in good faith, follow ethical guidelines, and comply with the policy terms.

9. Disclaimers

  • We reserve the right to modify this policy at any time without prior notice.
  • We do not guarantee recognition, reward, or compensation for disclosed vulnerabilities unless explicitly stated in a bug bounty program.

10. Contact

For all matters related to this policy, please contact:
Email: security@mediabirdco.net
Website: www.mediabirdco.net