Reference

Reporting a security issue

Found a security problem in Mochi Deploy? Here's how to tell us, and our commitment to you if you report it in good faith.

We take the security of Mochi Deploy seriously, and we welcome reports from anyone who finds a potential problem. If you believe you've found a vulnerability, please tell us before sharing it publicly, so we can look into it and fix it.

How to report

Email [email protected] with the details. A good report usually includes:

  • what you found, and why you think it's a problem;
  • the steps to reproduce it, or a short proof of concept;
  • the pages, addresses, or parts of the service involved; and
  • how we can reach you for any follow-up questions.

You don't need an account to report something, and you don't need to prove real-world impact. If something looks wrong, we'd rather hear about it.

Good-faith reports are welcome here
If you make a good-faith effort to follow the guidelines below, we won't pursue or support legal action against you for your research, and we'll treat your report as authorized. If someone else brings a claim against you for activity that followed these guidelines, we'll make it known that your actions were authorized.

Please do

  • give us a reasonable amount of time to fix an issue before you share it with anyone else;
  • only interact with accounts, workspaces, and data that belong to you, or that you have permission to test;
  • stop as soon as you've confirmed a problem, and don't go further than you need to in order to show it exists; and
  • keep the details of anything you find private until we've had a chance to address it.

Please don't

  • access, change, or delete data that isn't yours, or that you don't have permission to touch;
  • run tests that could degrade or interrupt the service for others, such as denial-of-service attempts or high-volume automated scanning;
  • use social engineering, phishing, or physical attempts against our team, our customers, or our providers; or
  • share, sell, or make public anything you find before we've resolved it.

What to expect

We'll acknowledge your report as soon as we reasonably can, look into it, and keep you posted as we work through it. Mochi Deploy doesn't run a paid bounty program today, so we can't promise a reward, but we're genuinely grateful for reports that help keep the service safe, and we're happy to credit you once an issue is fixed if you'd like.

For a broader look at how your data is protected, see Security.

Reporting a security issue · Mochi Deploy docs