Responsible Disclosure Policy
MiseCentral LLC ("MiseCentral," "we," "us," or "our") welcomes good-faith security research and responsible vulnerability reports regarding the Services, Website, and related infrastructure. This Responsible Disclosure Policy ("Policy") describes how security researchers may report potential vulnerabilities and how MiseCentral will handle such reports.
This Policy does not grant authorization to access Customer Data, production tenant environments, or systems beyond the scope described herein. Testing must not disrupt the Services or compromise the privacy or security of MiseCentral, its Customers, or third parties.
1. Scope
1.1. This Policy applies to good-faith security research and vulnerability reports concerning:
(a) the MiseCentral hosted Services and associated application programming interfaces made available to Customers under an Agreement;
(b) the Website and publicly accessible MiseCentral domains identified in Documentation; and
(c) MiseCentral-operated infrastructure supporting the Services, to the extent accessible without unauthorized access to Customer environments.
1.2. This Policy does not apply to:
(a) third-party Connected Services, partner systems, or Customer-managed integrations, except where a vulnerability in MiseCentral's integration layer is demonstrated without accessing a Customer's private data;
(b) social engineering, physical security testing, or denial-of-service attacks;
(c) spam, phishing, or malware distribution; or
(d) findings resulting from unauthorized access to Customer Data or Customer organizations.
1.3. For coordinated disclosure timelines and severity handling, see the Vulnerability Disclosure Policy, which complements this Policy.
2. Principles of Responsible Research
2.1. Researchers must act in good faith to avoid privacy violations, data destruction, service degradation, or harm to MiseCentral, Customers, or third parties.
2.2. Researchers must:
(a) make a good-faith effort to avoid accessing, modifying, or exfiltrating Customer Data or Personal Data;
(b) use only accounts and environments they own or for which they have explicit written authorization;
(c) stop testing immediately upon discovery of Customer Data exposure and report the finding without further exploitation;
(d) not publicly disclose a vulnerability before MiseCentral has had a reasonable opportunity to remediate, except as permitted under applicable law or as agreed in writing; and
(e) not demand payment or extortion as a condition of disclosure.
2.3. Prohibited activities include, without limitation: automated scanning at volumes that impair service availability; brute-force attacks against live credentials; attempting to bypass Support Mode or Partner Support Mode controls to gain unauthorized administrative access; and testing on production Customer organizations without authorization.
3. How to Report
3.1. Reports should be submitted to security@misecentral.com with the subject line "Responsible Disclosure Report."
3.2. To enable efficient triage, reports should include, to the extent possible:
(a) a description of the vulnerability and affected component;
(b) steps to reproduce, including proof-of-concept code or screenshots where helpful;
(c) the researcher's assessment of impact and severity;
(d) the researcher's contact information; and
(e) confirmation that the researcher agrees to this Policy.
3.3. MiseCentral may request additional information reasonably necessary to validate and remediate the report.
3.4. Researchers who prefer encrypted communication may request a secure channel through security@misecentral.com.
4. MiseCentral Response
4.1. MiseCentral will acknowledge receipt of valid reports within a commercially reasonable timeframe.
4.2. MiseCentral will investigate reported vulnerabilities, prioritize remediation based on severity and exploitability, and communicate status updates at reasonable intervals for substantiated issues.
4.3. MiseCentral may decline to act on reports that are out of scope, duplicate known issues, or lack sufficient detail for reproduction.
4.4. MiseCentral will not initiate legal action against researchers who comply with this Policy and applicable law in connection with a good-faith report, provided the researcher did not willfully violate law or access Customer Data without authorization.
5. Safe Harbor
5.1. Subject to Section 5.2, MiseCentral considers authorized security research under this Policy to be conducted with MiseCentral's consent for purposes of applicable anti-hacking laws to the extent such consent is recognized, provided the researcher complies with this Policy.
5.2. Safe harbor does not apply if the researcher:
(a) accesses, downloads, or retains Customer Data beyond the minimum necessary to demonstrate the vulnerability;
(b) intentionally disrupts the availability or integrity of the Services;
(c) violates applicable law; or
(d) violates the terms of an Agreement or Customer authorization.
5.3. Safe harbor is not a waiver of MiseCentral's rights against bad-faith actors, extortion, or activities outside this Policy's scope.
6. Recognition
6.1. MiseCentral may, at its discretion, acknowledge researchers who report qualifying vulnerabilities in accordance with this Policy, subject to the researcher's consent and MiseCentral's publication standards.
6.2. MiseCentral does not operate a paid bug bounty program unless separately announced in writing. This Policy does not create an entitlement to monetary compensation.
7. Customer and Partner Coordination
7.1. Vulnerabilities affecting Customer-specific configurations should be reported to MiseCentral. Researchers must not contact Customer organizations directly regarding vulnerabilities discovered through MiseCentral systems unless MiseCentral expressly coordinates such contact.
7.2. Partners who discover vulnerabilities during authorized implementation or support activities must report through security@misecentral.com and their Partner Agreement obligations.
8. Relationship to Other Policies
8.1. This Policy is complementary to the Vulnerability Disclosure Policy, Information Security Policy, and Website Acceptable Use Policy.
8.2. Nothing in this Policy modifies a Customer's Agreement, including liability limitations and indemnification obligations applicable to unauthorized testing.
9. Changes
9.1. MiseCentral may update this Policy by posting a revised version with an updated Effective Date and Last Updated date.
10. Contact
MiseCentral LLC Attn: Security — Responsible Disclosure 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.