Responsible Disclosure Policy
Last updated August 2026
We welcome good-faith security research on our own website and platform. If you believe you've found a vulnerability, tell us before you tell anyone else and we'll work the issue with you.
How to report
Email security@metaprotech.example with a clear description, the affected URL or endpoint, reproduction steps, and any supporting output. Please avoid sending third-party personal data in your report.
In scope
- This website and its public pages.
- The client portal and admin console authentication and authorization boundaries.
- Case data access controls, including attachment and signed-link handling.
Out of scope
- Denial-of-service, volumetric, or load testing of any kind.
- Social engineering of our staff, clients, or suppliers.
- Physical attacks, or attacks against third-party platforms we merely link to.
- Reports produced solely by an automated scanner with no demonstrated impact.
- Missing best-practice headers with no exploitable consequence.
Rules of engagement
Do not exploit an issue beyond what is needed to prove it exists. Do not access, modify, or retain data that isn't yours — if you encounter client data, stop and tell us. Use test accounts you created. Give us reasonable time to remediate before any public disclosure.
What you can expect
- Acknowledgement of your report within 3 business days.
- An initial assessment and severity view within 10 business days.
- Progress updates until the issue is resolved or formally closed.
- Credit in our acknowledgements if you'd like it, once a fix has shipped.
Note to the site owner: confirm these response windows match what your team can sustain before publishing them as a commitment.
Safe harbour
If you follow this policy in good faith, we will treat your research as authorized, will not pursue legal action against you, and will work with you on remediation. We do not currently operate a paid bug-bounty programme.