Responsible Disclosure Policy
Last updated: March 23, 2026
If you believe you have found a security vulnerability in Meshly, we encourage you to report it responsibly. We take all reports seriously and will respond promptly.
How to report
Email security@meshly.ai with:
- A description of the vulnerability
- Steps to reproduce
- Any supporting evidence (screenshots, logs, proof of concept)
What to expect
- We will acknowledge your report within 2 business days.
- We will investigate and provide an initial assessment within 5 business days.
- We will keep you informed of our progress toward a fix.
- Once resolved, we will notify you and credit you (if desired).
Guidelines
- Do not access, modify, or delete data belonging to other users.
- Do not disrupt or degrade Meshly services (no denial of service testing).
- Do not publicly disclose the vulnerability until we have had reasonable time to address it.
- Act in good faith and comply with all applicable laws.
Scope
- validate.meshly.ai (production application)
- meshly.ai (marketing site)
- Associated APIs
Out of scope
- Social engineering or phishing attacks against Meshly employees
- Physical security
- Third-party services and integrations
Recognition
We do not currently offer monetary rewards but will publicly acknowledge reporters who follow these guidelines (with permission).
Contact
For security reports, please email security@meshly.ai. For general inquiries, contact hello@meshly.ai.