Security

Security Disclosure Policy

Last updated: September 8, 2026

Reporting a security issue

If you believe you have found a security vulnerability in Monitorion, please report it to us at [email protected].

To help us respond quickly, please include: the affected product or URL, the type of issue, a brief description of the impact, and steps to reproduce. Do not include exploit code unless we request it.

What we ask of you

  • Avoid accessing, downloading, or modifying data that is not strictly necessary to demonstrate the issue.
  • Do not disrupt our services or other users while testing.
  • Give us a reasonable time to investigate and fix before any public disclosure.
  • Do not use the issue to compromise other users or systems.

What you can expect from us

  • We will acknowledge your report within 3 business days.
  • We will keep you informed of our progress and the resolution timeline.
  • We will not pursue legal action against good-faith, non-disruptive security research conducted in accordance with this policy (safe harbor).

Scope

This policy covers the Monitorion website, application, and APIs. Out-of-scope issues (for example, availability/DDoS, social engineering, or missing security headers with no demonstrated impact) may be acknowledged but are not prioritized.