Security
Responsible disclosure
We welcome responsible reports of potential security vulnerabilities that may affect mittiPaw, our website, or our services.
How to report
Email us at support@mittipaw.com. Where possible, please include:
- A clear description of the issue
- Affected page, feature, app version or service
- Steps to reproduce
- Screenshots or other supporting evidence, if useful
- Potential impact
- Contact details if you'd like a response
Please do not include passwords, authentication tokens, private keys, or other unnecessary sensitive information in your report.
Safe research expectations
To keep testing safe for everyone, we ask researchers to:
- Avoid accessing, changing or deleting another person's data
- Avoid privacy violations
- Avoid denial-of-service or resource-exhaustion testing
- Avoid social engineering
- Avoid destructive testing
- Use the minimum access necessary to demonstrate the issue
- Stop testing if you encounter personal or user data that isn't yours
- Give mittiPaw reasonable time to investigate before public disclosure
What to expect from us
We aim to acknowledge genuine security reports as promptly as practical and to keep reporters informed when further information is needed.
Bug bounty
mittiPaw does not currently operate a paid bug-bounty program. We're grateful for reports made in good faith regardless.
Out of scope
Some reports are unlikely to be actionable, including:
- Automated scanner output without evidence of real impact
- Social engineering
- Denial-of-service testing
- Physical attacks
- Vulnerabilities exclusively in unsupported third-party software with no impact to mittiPaw
