We are committed to maintaining the security and privacy of our systems and users. We welcome reports from ethical security researchers who follow responsible disclosure practices.
This policy applies to vulnerabilities that:
- Have a meaningful security impact.
- Affect our production systems or user data.
- Are discovered through manual, targeted testing.
Please note: We do not accept reports generated by automated scanners or tools that produce generic, low-quality findings (e.g., missing security headers, or outdated libraries without proven exploitability). Submissions of this nature will be disregarded.
If you believe you've found a valid security issue, please email us at informationsecurity@mapiq.com with:
- A clear and concise description of the issue.
- Steps to reproduce the vulnerability.
- Any relevant screenshots or proof-of-concept code.
We will acknowledge your report within 5 business days and aim to provide a status update within 10 business days.
To ensure responsible disclosure, please:
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Do not disrupt our services or systems.
- Do not perform automated scans or brute-force testing.
- We will investigate and validate legitimate reports.
- We will work to resolve confirmed issues promptly.
- We may publicly acknowledge your contribution if desired.
We appreciate your help in keeping our systems secure and thank you for acting responsibly.