Skip to main content

  1. MIRENA
  2. Trust
  3. Responsible Disclosure

Trust · Trust disclosure

Report a potential security issue without increasing the risk to users or systems.

This policy explains what to include in a report, where to send it, which testing is not authorised, how Semantec SEO handles reports, and how disclosure should be coordinated.

Public record

Verified facts and boundaries.

These fields identify the entity, product, document, or operational boundary without turning related parties into the same entity.

Report toprivacy@semantecseo.com
Suggested subjectSecurity report
Acknowledgement targetWithin 5 business days
Testing authorityNo blanket authorisation
User-data accessProhibited
Public disclosureCoordinate before publishing
01

Use the published report route.

Send a potential vulnerability or security concern to privacy@semantecseo.com with the subject 'Security report'. Product access issues that do not involve a security risk may use support@semantecseo.com.

A report should identify the affected URL or system, date and time, environment, observed behaviour, possible impact, and the minimum steps required to reproduce the issue safely.

02

Do not test beyond the minimum needed to report.

  • Do not access, modify, copy, delete, or expose another person's data
  • Do not use social engineering, phishing, credential attacks, or malware
  • Do not perform denial-of-service, load, stress, or resource-exhaustion testing
  • Do not attempt persistence, lateral movement, or privilege escalation beyond the observed issue
  • Do not bypass payment, entitlement, rate, safety, or account controls
  • Do not scan or test third-party systems without their written authorisation
  • Do not publish a live exploit or unremediated vulnerability before coordination
03

This page is not blanket testing permission.

The policy invites good-faith reporting of issues encountered through ordinary use or minimal verification. It does not authorise intrusive testing, access to non-public systems, access to user data, or testing of OpenAI, Stripe, Authflow.ai, hosting, email, or other third-party infrastructure.

Obtain written permission before testing beyond the published boundary.

04

Protect the evidence.

Send only the information necessary to assess the issue. Mask personal data, credentials, tokens, payment information, and confidential material. Use a secure transfer route if Semantec SEO requests one.

Do not include proprietary third-party code or data that you are not authorised to share.

05

How reports are handled.

Disclosure handling stages
Stage Semantec SEO action Reporter expectation
Acknowledgement Confirm receipt and assign a record Provide a reliable contact route
Triage Confirm scope, severity, ownership, and affected provider Answer proportionate clarification questions
Containment Reduce immediate risk where possible Do not continue testing without agreement
Remediation Repair the controlled system or route the issue to the provider Allow reasonable time based on risk and dependency
Verification Check the fix and affected routes Retest only within the agreed scope
Disclosure Agree whether and when public acknowledgement is suitable Do not publish before coordination
06

External platform issues.

A concern that belongs to OpenAI, Stripe, Authflow.ai, a hosting provider, or another external service may need to be reported through that provider's security channel. Semantec SEO can route a report when it affects its own service, but it cannot promise control over the provider's investigation or timeline.

07

Recognition and bounty.

Semantec SEO does not promise a financial bounty, reward, public credit, or safe-harbour commitment beyond the written scope of this policy. Any recognition is discretionary and subject to privacy, legal, and operational considerations.

Sources

Check the controlling first-party and official sources.

These routes support the current public statement. External platform and legal sources remain subject to their own updates.

Semantec SEO
Semantec SEO Acceptable Use

Current first-party security-testing and misuse restrictions.

Open source →

OpenAI
OpenAI usage policies

Official current platform safety requirements.

Open source →

Semantec SEO
Semantec SEO contact route

Current support and privacy contact information.

Open source →