Security & Vulnerability Disclosure

Last updated 27 July 2026

We take the security of MyIntelBrief seriously. If you have found a vulnerability that affects our service or our customers' data, we want to hear about it — and we'd rather hear about it from you than find out the hard way.

How to report

Email info@myintelbrief.com with “Security” in the subject line.

Please include enough detail for us to reproduce and verify the issue:

  • The affected URL, endpoint, or page
  • Step-by-step reproduction instructions
  • What an attacker could actually do with it (the impact)
  • Any supporting evidence — a request/response, screenshot, or short log excerpt

Our policy

What we consider out of scope

Automated scanner output with no demonstrated impact is generally not actionable for us. That includes, unless you can show a concrete exploit:

Testing boundaries

Please test only against your own account and your own data. Do not access, modify, or retain another customer's information; do not run denial-of-service or load tests; and do not use social engineering against our staff or our customers. If you encounter someone else's personal data during testing, stop, don't save it, and tell us what happened. We won't pursue action against anyone who follows these boundaries and reports in good faith.

A machine-readable version of this policy is published at /.well-known/security.txt (RFC 9116).
💬