Rec 00 · Policy

Security and responsible disclosure

Policy last reviewed: 13 August 2026 · Machine-readable version: /.well-known/security.txt

We run our own technology, and we would rather hear about a weakness from you than read about it later. If you believe you have found a security vulnerability in this website, the platform demo or any Meshads OÜ system, please report it.

How to report

Email business@meshads.com with the subject "Security". Include what you found, where (URL or system), and the steps to reproduce it. Proof-of-concept detail is welcome; exfiltrated data is not necessary to make your point.

What we commit to

  • We acknowledge your report within 5 business days.
  • We keep you informed while we investigate and fix.
  • We do not pursue legal action against research conducted in good faith under this policy.
  • If you want, we credit you once the issue is resolved.

What we ask of you

  • Give us reasonable time to fix the issue before any public disclosure.
  • Do not access, modify or delete data that is not yours; use test data wherever possible.
  • No denial-of-service testing, social engineering, physical attacks or spam.

We do not currently run a paid bug bounty program. Reports are handled on the same footing either way.