Responsible Disclosure Policy

Mediusware welcomes responsible security research that helps protect our website, systems, clients, and users. This page explains how to report a vulnerability safely, what information to include, and how we review security submissions.

Last updated: July 13, 2026

Help Us Keep Mediusware Secure

We value good-faith reports that help identify security weaknesses without harming users, clients, systems, or data. Please follow these principles when testing or reporting security concerns.

01

Report Responsibly

Report vulnerability details through the correct channel without public disclosure.

02

Protect Data

Do not access, modify, copy, delete, download, or expose client, user, employee, or business data.

03

Avoid Disruption

Do not interrupt services, degrade performance, run destructive tests, or attempt social engineering.

04

Give Us Time

Allow Mediusware reasonable time to review, validate, prioritize, and resolve submitted security issues.

01.

Overview

This Responsible Disclosure Policy explains how security researchers, users, clients, and partners can responsibly report suspected vulnerabilities related to Mediusware's website, digital platforms, public systems, or service-related security concerns.

We appreciate good-faith efforts that help us improve security. Reports are reviewed based on severity, clarity, reproducibility, affected systems, potential business impact, and remediation requirements.

02.

Scope

This policy applies to security concerns that may affect Mediusware-owned public web properties, official communication channels, and systems explicitly operated by Mediusware.

Public Website
Public Forms
Mediusware Systems
Authorized Client Scope
03.

Out Of Scope

Some reports may not qualify as actionable security issues, especially when they do not present meaningful risk, cannot be reproduced, or require unrealistic conditions.

Generic best-practice suggestions without a clear vulnerability.
Missing security headers that do not create practical exploitability.
Clickjacking or iframe concerns on pages with no sensitive action.
Social engineering, phishing simulations, or physical security attempts.
Denial-of-service testing, load testing, spam, or automated destructive scanning.
Issues affecting third-party services unless they directly compromise Mediusware-controlled assets.
04.

Safe Testing Rules

Researchers must test carefully and avoid actions that could harm Mediusware, our clients, users, data, systems, or service availability.

Use only accounts, test data, and systems you are authorized to access.
Do not access, modify, delete, download, or expose data that is not yours.
Do not run automated scans that could affect availability or performance.
Do not attempt persistence, lateral movement, malware upload, or privilege misuse.
Stop testing immediately if you encounter sensitive data or service instability.
Report findings promptly and confidentially.
05.

How To Report

If you believe you have discovered a security vulnerability, please contact Mediusware with a clear description of the issue and enough information for our team to reproduce and validate it.

06.

What To Include

A complete report helps us review the issue faster. Please include clear, concise, and reproducible details.

Affected URL, page, system, endpoint, or feature.
Step-by-step reproduction instructions.
Potential impact and who could be affected.
Proof-of-concept details, screenshots, request/response samples, or logs if safe to share.
Browser, device, account type, or environment used during testing.
Your name or preferred contact details for follow-up.
07.

Review Process

Mediusware reviews responsible disclosure submissions based on available information, severity, affected systems, and remediation complexity.

Receive
Review
Prioritize
Resolve
Follow Up
08.

Researcher Expectations

We ask researchers to act in good faith and help protect users, clients, and Mediusware systems while reporting security concerns.

Keep vulnerability details confidential until Mediusware has reviewed and addressed the issue.
Do not publicly disclose, sell, share, or exploit vulnerabilities.
Do not use the vulnerability to access or extract data.
Respect privacy, business continuity, and client confidentiality.
Provide reasonable time for review and remediation.
09.

Prohibited Actions

The following activities are not permitted and may result in restricted access, legal review, or reporting to relevant authorities where appropriate.

Denial-of-service attacks or performance degradation.
Social engineering, phishing, impersonation, or employee targeting.
Physical attacks, device tampering, or unauthorized office access.
Malware upload, backdoors, persistence, or destructive payloads.
Data exfiltration, credential theft, or unauthorized account access.
Testing on client-owned systems without written authorization.
10.

Recognition

Mediusware appreciates responsible security reports. At this time, Mediusware does not guarantee monetary rewards, bounty payments, public credit, or formal recognition for submissions.

Where appropriate, and only with mutual agreement, we may acknowledge helpful reports or maintain private communication with the researcher.

11.

Legal Note

Mediusware will review good-faith reports submitted under this policy and expects researchers to follow safe testing rules, avoid privacy violations, and not disrupt services. This policy does not grant permission to access, modify, destroy, or exfiltrate data.

12.

Related Trust & Security Resources

Continue reviewing Mediusware's security, privacy, compliance, and data handling resources before starting a software development engagement.

Security at Mediusware
Compliance at Mediusware
Data Processing Agreement
Cookie Policy
Privacy Policy
Request Security Documentation
13.

Contact Mediusware

If you have questions about this Responsible Disclosure Policy, security reporting, project security, or data protection, please contact Mediusware.