At Mainder, we take the security and privacy of our customers' data very seriously. We welcome responsible security research and are committed to working with researchers to verify and remediate vulnerabilities in a timely manner.
Email us at security@mainder.ai
We acknowledge reports within 3–5 business days
Good faith research is authorized and protected
This document describes our public Vulnerability Disclosure Program (VDP), which we also use as our lightweight bug bounty program.
https://mainder.aiIf you believe you have found a security vulnerability in a Mainder system or application, please report it to us as soon as possible by emailing:
Contact Email:
security@mainder.aiInclude as much detail as possible:
⚠️ Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate it.
Acknowledge receipt of your report within 3–5 business days.
Evaluate the reported issue, assign a severity, and determine whether it is in scope.
Work to remediate validated vulnerabilities in a timely manner, prioritising high and critical severity issues.
Keep you informed of the status of your report (triaged, in progress, fixed, etc.), subject to our internal processes and confidentiality obligations.
We will not initiate legal action against researchers for security research performed in good faith and in accordance with this policy. As long as you:
We will treat your research as authorized and will work with you to resolve the issue.
At this time, Mainder does not operate a formal paid bug bounty program with monetary rewards. However:
All vulnerability reports will be handled confidentially. Any personal data that you share with us as part of the report will be processed solely for the purpose of triaging, reproducing, and fixing the vulnerability, in line with our privacy and data protection obligations.
If you have any questions about this policy or are unsure whether a test is in scope, please contact us at:
Contact Security Team