Responsible disclosure guidelines for security researchers and users.
Security Commitment
At MCQs Mind, we take security very seriously. We protect user accounts, data, and the platform against security threats using standard practices.
We welcome responsible, ethical reports of vulnerabilities from security researchers and users. We work to patch reported problems in a timely manner.
Scope of Vulnerabilities
In-scope targets: `mcqsmind.com`, `app.mcqsmind.com`, and all owned subdomains.
Out-of-scope targets: Third-party services we use (e.g. Hostinger, Cloudflare, Google Analytics), social engineering or phishing of our staff, physical security, denial-of-service (DoS/DDoS) attacks, or automated scanner logs without clear proof of exploitability.
How to Report a Vulnerability
If you identify a security issue, please email [email protected] with details.
Please include:
- Description of the vulnerability and its potential impact.
- Step-by-step reproduction steps (text, image, or video PoC).
- Any recommended patch or remediation step (optional).
Our Commitments to You
For ethical disclosures that follow this policy, we commit to:
- Acknowledging your report within 3 business days.
- Providing status updates as we research and patch the issue.
- Crediting your assistance (on our hall of fame, if desired) once resolved.
- Refraining from taking legal action against your research.
Research Rules
- Do NOT access, modify, or destroy user data or system resources.
- Do NOT exfiltrate data beyond what is needed to prove the bug.
- Do NOT perform load testing or denial-of-service tests.
- Keep all details private until we have successfully resolved the issue.