Responsible Disclosure Policy

    Last updated: March 23, 2026

    If you believe you have found a security vulnerability in Meshly, we encourage you to report it responsibly. We take all reports seriously and will respond promptly.

    How to report

    Email security@meshly.ai with:

    • A description of the vulnerability
    • Steps to reproduce
    • Any supporting evidence (screenshots, logs, proof of concept)

    What to expect

    • We will acknowledge your report within 2 business days.
    • We will investigate and provide an initial assessment within 5 business days.
    • We will keep you informed of our progress toward a fix.
    • Once resolved, we will notify you and credit you (if desired).

    Guidelines

    • Do not access, modify, or delete data belonging to other users.
    • Do not disrupt or degrade Meshly services (no denial of service testing).
    • Do not publicly disclose the vulnerability until we have had reasonable time to address it.
    • Act in good faith and comply with all applicable laws.

    Scope

    • validate.meshly.ai (production application)
    • meshly.ai (marketing site)
    • Associated APIs

    Out of scope

    • Social engineering or phishing attacks against Meshly employees
    • Physical security
    • Third-party services and integrations

    Recognition

    We do not currently offer monetary rewards but will publicly acknowledge reporters who follow these guidelines (with permission).

    Contact

    For security reports, please email security@meshly.ai. For general inquiries, contact hello@meshly.ai.