Skip to content
M&L AI

Security

Reporting a Vulnerability

This website welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issue in any of our assets, we want to hear from you.

Official Channels

Please report security issues via one of the following channels, providing as much detail as possible. The more information you include, the easier it will be for us to triage and address the issue.

Systems in Scope

This policy covers any digital assets owned, operated, or maintained by mlaify.io, including:

What We Ask of You

Please give us at least 90 days from your initial report to resolve the issue before any public disclosure.

When participating in our vulnerability disclosure program in good faith, we ask that you:

  • Follow our Vulnerability Disclosure Policy and any other applicable agreements;
  • Report vulnerabilities promptly and avoid violating the privacy of others or disrupting our systems;
  • Limit data access to the minimum required for a Proof of Concept;
  • Cease testing and report immediately if you encounter any user data (PII, PHI, financial data); and
  • Not engage in extortion.

Our Commitments

You can expect us to:

  • Respond to your report promptly and work with you to understand and validate it;
  • Keep you informed about the progress of the vulnerability as it is processed;
  • Remediate confirmed vulnerabilities in a timely manner; and
  • Extend Safe Harbor for good-faith research conducted under this policy.

Safe Harbor

We consider security research conducted under this policy to be authorized under applicable anti-hacking and anti-circumvention laws. We will not initiate or support legal action against researchers who act in good faith in accordance with this policy.


For the complete policy text, see SECURITY.md in our repository.

This policy follows the disclose.io vulnerability disclosure framework.


Thank you for helping keep this site secure.