generated: '2026-09-19' method: searched probe: true source: https://mandateshield.com/responsible-disclosure policy: - https://mandateshield.com/responsible-disclosure contact: - mailto:support@hemelion.com - https://mandateshield.com/responsible-disclosure evidence: - source: well-known/mandateshield-com-security.txt kind: security.txt (Policy and Contact fields) - source: https://mandateshield.com/responsible-disclosure http_status: 200 fetched: '2026-09-19' keywords: - Responsible Disclosure Policy - safe harbor - security report - bug bounty (explicitly not promised) docs: https://mandateshield.com/responsible-disclosure bug_bounty: false bounty_note: '"MandateShield does not currently promise a bug bounty, payment or a fixed response time. Any reward must be expressly confirmed in writing before reliance."' platform: null safe_harbor: true safe_harbor_text: Good-faith research following the policy is treated as authorized under the Acceptable Use Policy; MandateShield will not initiate legal action solely for accidental, good-faith violations. Cannot bind third parties or law enforcement. scope: in: - MandateShield-owned production domains and API routes - the public sandbox - published MandateShield SDKs and packages - MandateShield-controlled proof and receipt verification surfaces out: - Stripe, OpenAI, Cloudflare, GitHub, blockchain RPC infrastructure, customer systems and other third-party services prohibited: - social engineering - physical attacks - spam - extortion - denial-of-service or load testing - credential stuffing - mass account creation - malware, persistence, lateral movement, destructive actions - automated scanner output without demonstrated impact reporting: email: support@hemelion.com subject: MandateShield security report include: - affected URL, route or package version - impact - reproducible steps - timestamps - sanitized evidence exclude: - live credentials - payment data - another person's personal data response_time: none promised disclosure: Give reasonable remediation time before public disclosure; delete retained test data after confirmation. security_txt: file: well-known/mandateshield-com-security.txt expires: '2027-07-26T23:59:59Z' canonical_matches: true