Trust
Report a Vulnerability
How to report a security vulnerability in TapMind systems or services.
Report a vulnerability
Describe the issue with enough detail for our security team to investigate. Do not include passwords, secrets, or other people’s data.
TapMind takes the security of its websites, applications, platforms, APIs, SDKs, and related Services seriously.
If you believe you have discovered a security vulnerability affecting a TapMind system or Service, we encourage you to report it responsibly so that our security team can investigate and address it.
This Policy describes how to submit a vulnerability report and the principles TapMind applies when reviewing responsible security disclosures.
1. What to Report
Please report vulnerabilities that may affect the confidentiality, integrity, or availability of TapMind systems or data.
Examples may include:
- authentication or authorization vulnerabilities;
- access-control issues;
- exposure of sensitive information;
- injection vulnerabilities;
- cross-site scripting (XSS);
- server-side request forgery (SSRF);
- insecure API endpoints;
- security configuration issues;
- cryptographic weaknesses;
- vulnerabilities affecting SDKs or integrations;
- remote code execution; and
- other security weaknesses that could reasonably create a material risk to TapMind or its users.
If you are uncertain whether an issue qualifies, we encourage you to report it.
2. How to Submit a Report
Please submit vulnerability reports to:
- Security Email: security@tapmind.com
Security Contact/Portal: /trust/vulnerability-disclosure
Please do not include unnecessary Personal Data, credentials, secrets, or other sensitive information in your initial report.
Where possible, include:
- a clear description of the vulnerability;
- the affected TapMind product, domain, application, API, SDK, or component;
- steps required to reproduce the issue;
- proof-of-concept code or demonstration, where appropriate;
- the potential security impact;
- relevant request or response information;
- screenshots or supporting evidence, where useful; and
- any suggested remediation, if available.
3. Responsible Testing
Security testing should be conducted responsibly and with the minimum level of access and activity necessary to demonstrate the vulnerability.
Researchers should:
- avoid accessing data that does not belong to them;
- avoid modifying, deleting, or corrupting data;
- avoid disrupting or degrading TapMind Services;
- avoid social engineering or physical attacks against TapMind personnel;
- avoid introducing persistent malware or backdoors;
- stop testing once sufficient evidence has been obtained; and
- promptly report the vulnerability to TapMind.
Where possible, use test accounts and test data rather than real user or customer information.
4. Activities That Are Not Permitted
Researchers should not:
- perform denial-of-service or distributed denial-of-service attacks;
- conduct destructive testing;
- intentionally disrupt production systems;
- access, modify, copy, or delete data belonging to other users or customers;
- conduct phishing, social engineering, or credential attacks against personnel;
- deploy malware, ransomware, or persistent access mechanisms;
- perform physical security attacks;
- publicly disclose a vulnerability before allowing TapMind reasonable time to investigate and address it; or
- use a discovered vulnerability for personal gain, fraud, or other unlawful activity.
Testing that creates significant operational, privacy, security, or legal risk may not be considered responsible disclosure.
5. Personal Data and Sensitive Information
If vulnerability testing unintentionally exposes Personal Data or other sensitive information:
- stop accessing the information;
- do not copy, retain, disclose, or further use it;
- report the exposure to TapMind promptly; and
- securely delete any information obtained unintentionally, where legally and technically possible.
Please include only the minimum evidence necessary to demonstrate the vulnerability.
6. Third-Party Systems
TapMind's Services may integrate with third-party platforms, advertising technologies, infrastructure providers, SDKs, APIs, and other systems.
If you identify a vulnerability that appears to exist entirely within a third-party system, please report it to the relevant provider where appropriate.
If the issue affects the way TapMind integrates with or uses that third-party system, you may also report it to TapMind so that we can investigate our portion of the implementation.
7. What You Can Expect From TapMind
After receiving a vulnerability report, TapMind will make reasonable efforts to:
- acknowledge receipt where practicable;
- assess the reported issue;
- investigate and validate the vulnerability;
- communicate with the reporter where additional information is required;
- determine appropriate remediation;
- address confirmed vulnerabilities according to their severity and risk; and
- provide updates where appropriate.
Response and remediation timelines may vary depending on the severity, complexity, affected systems, available evidence, and operational impact of the reported issue.
8. Good-Faith Research
TapMind appreciates good-faith security research.
Where a researcher follows this Policy, acts responsibly, avoids prohibited activities, and does not exploit a vulnerability beyond what is reasonably necessary to demonstrate it, TapMind will consider that conduct when evaluating the report.
This Policy does not grant permission to violate applicable law, access systems or data beyond what is reasonably necessary for responsible testing, or disregard contractual or technical restrictions.
9. Coordinated Disclosure
Please give TapMind a reasonable opportunity to investigate and remediate a reported vulnerability before publicly disclosing it.
If you believe public disclosure is necessary or appropriate, please discuss the proposed disclosure timeline with TapMind in advance where practicable.
TapMind may coordinate with affected customers, technology providers, security researchers, or other relevant parties where necessary to address a vulnerability.
10. Duplicate and Informational Reports
TapMind may receive multiple reports concerning the same vulnerability or issue.
Where appropriate, TapMind may treat substantially identical reports as duplicates.
Reports that do not identify a security vulnerability or actionable security risk may be handled as general security feedback rather than as vulnerability disclosures.
11. Scope
This Policy applies to TapMind systems and Services that TapMind identifies as within the scope of its vulnerability-reporting program.
Third-party systems, customer-controlled infrastructure, and systems that TapMind does not operate may fall outside the scope of this Policy.
12. No Guarantee of Reward
Unless TapMind expressly operates a bug-bounty program, submitting a vulnerability report does not create an entitlement to monetary compensation, employment, recognition, or any other reward.
13. Confidentiality
Researchers should treat non-public information obtained during security testing as confidential and should not disclose it to third parties except as required by law or agreed with TapMind.
TapMind will handle vulnerability reports and information provided by researchers in accordance with its applicable security and privacy practices.
14. Policy Changes
TapMind may update this Policy from time to time to reflect changes to:
- its Services;
- security practices;
- vulnerability-reporting procedures;
- applicable laws; or
- the scope of its security program.
The latest version will be published with a revised Last Updated date.
15. Contact
Security vulnerabilities should be reported to:
- TapMind Security Team
Security Email: security@tapmind.com
Security Reporting Portal: /trust/vulnerability-disclosure
For general privacy matters, please contact:
- Privacy Email: dpo@tapmind.com