Security
Vulnerability disclosure policy
Last updated: 2026-08-30. This policy covers the Miatz website, the Miatz web application and the Miatz mobile apps, all operated by Miatz Private Limited. The machine-readable version is served at /.well-known/security.txt.
If you have found a security weakness in miatz, we want to hear about it, and we would rather hear about it from you than from an incident. Email hello@miatz.com with the subject line Security report. Research done inside the rules below is authorised research, and we will treat it that way.
1. What is in scope
- miatz.com and its subdomains, including the logged-in application and the public API served under
/api. - The miatz mobile apps for Android and iOS, and the deep-link association files they rely on.
- Anything that crosses a tenant or learner boundary — data belonging to another person or another organization reachable from an account that should not see it is the finding we care about most.
2. How to report
Email hello@miatz.com. A report we can act on the same day usually has:
- the URL, endpoint or screen, and the account or role you were using;
- the steps to reproduce, in order, and what you saw at the end of them;
- why it matters — the data or action it exposes, not a scanner severity;
- any log, request or screenshot that shortens our reproduction.
Please do not open a public issue, post the details, or send them through the contact form before we have had a chance to fix the problem.
3. What happens next
These are the targets we hold ourselves to, counted from when your email arrives:
- Acknowledgement within three business days, from a person rather than an autoresponder.
- A first assessment within ten business days, telling you whether we reproduced it and how we have rated it.
- An update at least every fourteen days until the report is closed, and a note when the fix ships.
We aim to remediate a critical finding within seven days and everything else within the following release cycle. Where a fix will take longer than that, we will say so and tell you why.
4. Safe harbour
If you follow this policy in good faith, we will treat your work as authorised: we will not pursue or support legal action against you over it, we will not report you to your employer or your host, and if a third party raises a claim about research that stayed inside these rules, we will say publicly that it was authorised.
This protection covers the testing, not everything that might follow it. Exfiltrating personal data, extortion, or selling a finding are outside it, and outside the law.
5. Rules of engagement
- Test against accounts you own. Signing up is free, so make as many as you need.
- Stop at proof. Once you can see that a boundary is crossed, do not read, copy, change or delete anyone else’s data, and tell us instead of going further.
- No denial of service, no load or stress testing, no mass automated scanning against production, and nothing that degrades the service for learners using it.
- No social engineering of our team, our mentors or our learners, and no physical intrusion.
- Give us ninety days from your report before publishing, and talk to us first if you want to publish sooner.
6. Out of scope
These are usually closed without a fix. Send them anyway if you can show a working path to real impact — the impact is what takes a report out of this list.
- Findings in a third-party service we use — report those to the vendor, and tell us the ticket.
- Missing hardening headers, cookie flags or TLS configuration with no demonstrated exploit.
- Raw output from an automated scanner, and version numbers with no reachable weakness.
- Self-inflicted issues: self-XSS, findings that need a rooted device or an already-compromised browser.
- Email configuration advice, rate-limit opinions and clickjacking on pages that take no action.
- Content, copy and accessibility reports — welcome, but send those to the contact form.
7. Recognition
We do not run a paid reward programme today. What we do offer is a straight answer, a fix you can verify, and public credit on request once the fix has shipped. If that changes, this page changes with it.
8. Contact
Security reports: hello@miatz.com. Everything else goes through our contact page. See also our Privacy Policy and Terms of Service.