Report a vulnerability
Email support@vymeros.com with a clear description, the affected URL or feature, reproduction steps and any proof-of-concept output. Please give us a reasonable time to fix the issue before disclosing it publicly.
Guidelines for testing
- Only test against accounts you own or have permission to use.
- Do not access, modify or delete other users' data — stop as soon as you confirm an issue.
- No denial-of-service, spam, brute-force or social-engineering of our staff or users.
- No physical attacks and no automated scanning that degrades the service.
- Follow applicable law at all times.
We do not currently operate a paid bug bounty programme and cannot promise a reward or legal safe harbour beyond acting in good faith toward researchers who follow these guidelines.
In scope
- The Mind Spark web app and installable PWA.
- Authentication, session handling and access-control flaws.
- Data exposure through APIs, database policies or file storage.
- Stored or reflected cross-site scripting and injection issues.
Out of scope
- Missing best-practice headers with no demonstrated impact.
- Reports produced only by automated scanners without a working proof of concept.
- Vulnerabilities in third-party providers — report those to the provider.
- Content or moderation complaints — use Safety & Reporting instead.
Platform abuse
For spam networks, bot farming, coordinated leaderboard manipulation or mass fake accounts, email support@vymeros.com with usernames and examples.
What to expect
We acknowledge reports as quickly as we can, investigate, and let you know the outcome. Fix timelines depend on severity and complexity.