Security Program

Vulnerability Disclosure Policy

MarketMind AI values the security research community. If you discover a security vulnerability in our platform, we ask that you report it to us responsibly so we can address it promptly and protect our customers.

Last updated: August 2026

How to Report

Email vulnerability details to security@marketmindai.cloud. For sensitive reports, encrypt your message using our PGP public key.

Include a clear description of the vulnerability, steps to reproduce, and potential impact. We acknowledge all reports within 48 hours and provide status updates throughout remediation.

Scope

In Scope
  • •MarketMind AI production web application (marketmindai.cloud)
  • •MarketMind AI API endpoints and SDK surfaces
  • •Authentication and session management systems
  • •Cloud infrastructure misconfigurations exposing customer data
Out of Scope
  • •Denial of Service (DoS/DDoS) attacks against production services
  • •Social engineering or phishing of MarketMind AI staff or contractors
  • •Physical attacks against data center or office facilities
  • •Vulnerabilities in third-party services not controlled by MarketMind AI
  • •Findings from automated scanners without demonstrated exploitability

Recognition & Rewards

SeverityRecognitionCriteria
CriticalHall of Fame + SwagRCE, SQL injection, or full tenant data exposure
HighHall of Fame + SwagPrivilege escalation or auth bypass
MediumHall of Fame + SwagXSS, CSRF, or sensitive data leak
LowHall of FameSecurity misconfiguration or information disclosure

All accepted reports are credited on our Hall of Fame. Monetary rewards may be introduced post-seed funding; today all accepted reports are recognized via Hall of Fame placement and swag.

Safe Harbor

Good Faith Participation

Researchers who discover and report vulnerabilities in accordance with this policy act in good faith. MarketMind AI will not pursue legal action against such reports.

Confidentiality

Researchers must not publicly disclose vulnerability details before a fix is deployed and MarketMind AI has granted permission for publication.

No Exploitation

Researchers must not access, modify, or destroy data belonging to other tenants. Testing must be limited to the minimum necessary to demonstrate the vulnerability.

Response Timeline

Report acknowledgmentWithin 48 hours
Initial assessment & triageWithin 5 business days
Fix deployment (critical)Within 30 days
Public disclosure (if permitted)After fix deployed

Report vulnerabilities to security@marketmindai.cloud