Vulnerability Disclosure Policy
Reporting security issues.
This policy tells security researchers how to report vulnerabilities to us, what's in scope, and what you can expect in return.
Our commitment
Mobedo takes the security of its systems seriously. We welcome good-faith reports from security researchers and treat them as help, not hostility - if you've found something, we want to hear about it and fix it.
Scope
In scope
- mobedoconsulting.com and its subdomains
Out of scope
- Third-party services and vendor systems we use but don't control
- Physical testing of offices or equipment
- Social engineering of Mobedo staff, clients, or partners
- Denial-of-service testing or anything that degrades the site for other users
How to report
Send reports to security@mobedoconsulting.com. Encrypt sensitive details if you prefer; what matters most is reaching a human who reads this address.
What to include
- A description of the issue and where you found it
- Steps to reproduce it
- Your assessment of the potential impact
Do not include personal or financial data in the report itself - yours or anyone else's. If your finding involves such data, describe it; don't exfiltrate or attach it.
Our commitment to you
Good-faith security research conducted within the scope of this policy will not result in legal action from us. We consider research in scope when it respects the exclusions above, avoids harming users or data, and is reported to us before any public disclosure.
What to expect
- Acknowledgment of your report within 2 business days].
- An assessment of severity and, where confirmed, a remediation plan appropriate to the risk.
- A note back to you when the issue is resolved, where practical.
We do not promise a fixed public disclosure deadline; we ask for reasonable time to remediate before disclosure, and we'll coordinate with you on timing.
