Safe harbor
If you make a good-faith effort to follow this policy, MandateShield will treat your research as authorized under the Acceptable Use Policy and will not initiate legal action solely for accidental, good-faith violations of this policy. This authorization cannot bind third parties or law-enforcement authorities and does not authorize testing third-party systems.
In scope
MandateShield-owned production domains and API routes, the public sandbox, published MandateShield SDKs and packages, and MandateShield-controlled proof and receipt verification surfaces. Use only accounts, credentials and data you own or are expressly authorized to test.
Out of scope and prohibited methods
Stripe, OpenAI, Cloudflare, GitHub, blockchain RPC infrastructure, customer systems and other third-party services are out of scope. Do not use social engineering, physical attacks, spam, extortion, denial-of-service or load testing, credential stuffing, mass account creation, malware, persistence, lateral movement, destructive actions or automated scanner output without demonstrated impact.
Research rules
- Minimize requests and data access.
- Stop immediately if you encounter another person's data.
- Do not download, alter, retain or disclose third-party data.
- Do not access funds or execute a real payment.
- Give reasonable remediation time before public disclosure and delete retained test data after confirmation.
How to report
Email support@hemelion.com with the affected URL, route or package version; impact; reproducible steps; timestamps; and sanitized evidence. Do not send live credentials, payment data or another person's personal data. Use the subject “MandateShield security report.”
MandateShield does not currently promise a bug bounty, payment or a fixed response time. Any reward must be expressly confirmed in writing before reliance.