MenerFlow legal
Vulnerability Disclosure Policy
How to report a potential MenerFlow security weakness safely and in good faith.
- Version
- 2026-07-27
- Effective
- July 27, 2026
1. Reporting
Email admin@meneraihq.com with subject “MenerFlow security report.” Include the affected URL/component, clear reproduction steps, observed impact, minimum redacted evidence, testing time, and a safe contact method. Ask for secure transfer if sensitive evidence is unavoidable.
2. Good-faith boundaries
- Use an account and synthetic data you are authorized to control.
- Stop immediately on another tenant's data, a secret, or active compromise.
- Do not use social engineering, malware, denial of service, persistence, destruction, extortion, or high-volume scanning.
- Do not test a MenerFlow provider without that provider's separate authorization.
- Do not send real email, SMS, or calls to uncontrolled recipients.
- Access no more information than necessary to demonstrate the issue.
3. Process and disclosure
Menerai will prioritize credible reports, verify scope, preserve evidence, coordinate remediation, and communicate as practical. No response time, resolution time, payment, bounty, or public credit is promised. Coordinate disclosure timing so affected people can be protected. A researcher is not authorized to make commitments or notices for Menerai.