Report a Security Issue
Email [email protected] with the subject “Security report.” Do not include passwords, access tokens, private keys, customer records, or other sensitive data in the initial message.
Please include the affected service or URL, a clear description of the issue and potential impact, reproducible steps or a minimal proof of concept, and a safe way to contact you. We aim to acknowledge a complete report within three business days and will provide status updates as we investigate and remediate confirmed issues.
Responsible Testing
If you conduct security research, please act in good faith and:
- Test only accounts, systems, and data you own or are explicitly authorized to use;
- Avoid privacy violations, data destruction, service disruption, denial-of-service testing, social engineering, spam, or high-volume automated scanning;
- Stop testing and report promptly if you encounter customer data, credentials, or a path to material unauthorized access;
- Use the minimum interaction necessary to demonstrate the issue; and
- Allow us reasonable time to investigate and remediate before public disclosure.
What to Expect
We will track the report, assess severity and scope, preserve relevant evidence, coordinate remediation with affected providers or customers when necessary, and communicate resolution. We may ask for additional technical detail or identity verification before sharing non-public status information.
Good-Faith Research
Meier Made will not pursue legal action against researchers for accidental, good-faith violations of this policy when they avoid harm, respect privacy, do not exploit the issue beyond what is needed to demonstrate it, and comply with applicable law. This statement does not authorize testing of third-party platforms or infrastructure that Meier Made does not own.
Privacy or Data Concerns
For a privacy concern or request to delete information, use our Privacy Policy and Data Deletion instructions.
