Vulnerability Disclosure Policy
Effective Date: 2 October 2026
Last Updated: 2 October 2026
Version: 2026-10-02
1. Why this policy exists
A data room holds other people's confidential material, so we want to hear about a weakness before anyone exploits it. If you find one, please tell us, and we will treat you fairly. This policy tells you how to test safely, how to report, and what to expect.
2. What is in scope
- the MandateRoom website and web application, and the programming interfaces they use;
- the server-side functions of the Service that we operate.
Out of scope: the infrastructure and services of our providers (report those to the provider); social engineering or phishing of our staff, customers or users; physical attacks; denial-of-service and volumetric testing; high-rate automated scanning; spam; reports of a missing best-practice header or setting with no demonstrated impact; and any account or Room that is not yours.
3. How to test safely
- Use your own accounts. Create test accounts in the normal way. If you want a test Room to work in, ask us. Never test against a customer's Room or another person's account.
- Do not read, change, delete or keep other people's data. If you reach data that is not yours, stop at once, do not look further, do not copy it, and tell us what you did.
- Do not harm the Service. Do not degrade it, lock out other users or leave anything behind.
- Keep it to yourself until it is fixed. Please give us a reasonable time to fix a problem before you tell anyone else, and do not use what you find to demand payment.
4. Our promise to you (safe harbour)
If you act in good faith and follow this policy, we regard your research as authorised. We will not bring or support a legal action against you, and we will not report you to an authority, for that research. If a third party, or an authority, brings a claim against you for activity that this policy covers, we will say that your work was authorised. We cannot bind third parties, such as our providers, or an authority that acts on its own, and this policy does not authorise anything that it does not describe.
5. What to send
Email hello@mandateroom.com with "Security report" in the subject line. Tell us what you found, where, the steps to reproduce it, what an attacker could do with it, and any proof of concept, with how to reach you. Please do not attach another person's data.
6. What to expect
- We acknowledge your report within three business days.
- We give you an initial assessment within ten business days, and an update at least every 14 days until the issue is resolved.
- We aim to fix critical issues within seven days and others in order of severity. We will tell you if we need longer and why.
- With your permission, we will credit you publicly once the issue is fixed. We do not pay rewards, and we say so so that you are not misled.
7. Disclosure
We prefer coordinated disclosure. We ask that you wait until we have fixed the issue or 90 days have passed since your report, whichever is first, and we will work with you on the date and on the wording of any public advisory.
8. Machine-readable contact
Our contact details for security reports are also published in the standard location, /.well-known/security.txt.