Security

Responsible disclosure

We welcome responsible reports of potential security vulnerabilities that may affect mittiPaw, our website, or our services.

How to report

Email us at support@mittipaw.com. Where possible, please include:

  • A clear description of the issue
  • Affected page, feature, app version or service
  • Steps to reproduce
  • Screenshots or other supporting evidence, if useful
  • Potential impact
  • Contact details if you'd like a response

Please do not include passwords, authentication tokens, private keys, or other unnecessary sensitive information in your report.

Safe research expectations

To keep testing safe for everyone, we ask researchers to:

  • Avoid accessing, changing or deleting another person's data
  • Avoid privacy violations
  • Avoid denial-of-service or resource-exhaustion testing
  • Avoid social engineering
  • Avoid destructive testing
  • Use the minimum access necessary to demonstrate the issue
  • Stop testing if you encounter personal or user data that isn't yours
  • Give mittiPaw reasonable time to investigate before public disclosure

What to expect from us

We aim to acknowledge genuine security reports as promptly as practical and to keep reporters informed when further information is needed.

Bug bounty

mittiPaw does not currently operate a paid bug-bounty program. We're grateful for reports made in good faith regardless.

Out of scope

Some reports are unlikely to be actionable, including:

  • Automated scanner output without evidence of real impact
  • Social engineering
  • Denial-of-service testing
  • Physical attacks
  • Vulnerabilities exclusively in unsupported third-party software with no impact to mittiPaw

Related pages