MarketMind AI values the security research community. If you discover a security vulnerability in our platform, we ask that you report it to us responsibly so we can address it promptly and protect our customers.
Last updated: August 2026
Email vulnerability details to security@marketmindai.cloud. For sensitive reports, encrypt your message using our PGP public key.
Include a clear description of the vulnerability, steps to reproduce, and potential impact. We acknowledge all reports within 48 hours and provide status updates throughout remediation.
| Severity | Recognition | Criteria |
|---|---|---|
| Critical | Hall of Fame + Swag | RCE, SQL injection, or full tenant data exposure |
| High | Hall of Fame + Swag | Privilege escalation or auth bypass |
| Medium | Hall of Fame + Swag | XSS, CSRF, or sensitive data leak |
| Low | Hall of Fame | Security misconfiguration or information disclosure |
All accepted reports are credited on our Hall of Fame. Monetary rewards may be introduced post-seed funding; today all accepted reports are recognized via Hall of Fame placement and swag.
Researchers who discover and report vulnerabilities in accordance with this policy act in good faith. MarketMind AI will not pursue legal action against such reports.
Researchers must not publicly disclose vulnerability details before a fix is deployed and MarketMind AI has granted permission for publication.
Researchers must not access, modify, or destroy data belonging to other tenants. Testing must be limited to the minimum necessary to demonstrate the vulnerability.
Report vulnerabilities to security@marketmindai.cloud