Reporting a security issue

If you've found a security vulnerability in MTDLite, we want to know about it. Please report it responsibly, before disclosing it publicly, so we have a chance to fix it first.

How to report

Email [email protected] with as much detail as you can, including:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce it (a proof of concept, if you have one)
  • The URL, endpoint, or component affected
  • Any tools or scripts used to find it

What to expect

We aim to acknowledge reports within 5 working days, and to keep you updated on progress as we investigate and fix the issue. Please give us a reasonable amount of time to address a vulnerability before disclosing it publicly.

Please don't

  • Access, modify, or delete data that isn't yours
  • Run automated scanning tools that could degrade the service for real users
  • Publicly disclose a vulnerability before we've had a chance to fix it

Machine-readable contact

A security.txt file (RFC 9116) is available at /.well-known/security.txt for automated tools.

Thank you for helping keep MTDLite and its users safe.

Back