Security & Vulnerability Disclosure
Last updated 27 July 2026
We take the security of MyIntelBrief seriously. If you have found a vulnerability
that affects our service or our customers' data, we want to hear about it — and
we'd rather hear about it from you than find out the hard way.
How to report
Email info@myintelbrief.com
with “Security” in the subject line.
Please include enough detail for us to reproduce and verify the issue:
- The affected URL, endpoint, or page
- Step-by-step reproduction instructions
- What an attacker could actually do with it (the impact)
- Any supporting evidence — a request/response, screenshot, or short log excerpt
Our policy
-
We do not pay bounties. We have no paid bug-bounty programme and no
budget for one. We will not negotiate a payment in exchange for the details of a
report. If that is a dealbreaker for you, please don't spend your time — we'd rather
be straightforward about it up front than waste yours.
-
We will not respond to reports that withhold the finding. A message
saying a vulnerability exists but declining to describe it until we reply, agree to
terms, or discuss compensation is not a security report, and we won't engage with it.
Send the details or don't send anything.
-
We read every report that includes reproduction steps, and we
investigate the ones that check out. We're a small team, so we don't guarantee a
response time, and we may not reply to reports we can't reproduce or that describe
no real impact.
-
Credit, if you want it. If you report something real and you'd like
to be acknowledged publicly, tell us and we'll be glad to name you once it's fixed.
What we consider out of scope
Automated scanner output with no demonstrated impact is generally not actionable for us.
That includes, unless you can show a concrete exploit:
- Missing or “weak” HTTP security headers
- SPF / DKIM / DMARC configuration opinions
- Missing rate limits with no demonstrated abuse
- Software version fingerprinting, banner grabbing, or “outdated library” reports without a working exploit
- Self-XSS, clickjacking on pages with no sensitive action, or issues requiring a fully compromised device
- Denial of service, volumetric testing, or anything that degrades service for real users
Testing boundaries
Please test only against your own account and your own data. Do not access, modify, or
retain another customer's information; do not run denial-of-service or load tests; and
do not use social engineering against our staff or our customers. If you encounter
someone else's personal data during testing, stop, don't save it, and tell us what
happened. We won't pursue action against anyone who follows these boundaries and reports
in good faith.