Security Policy
How to report vulnerabilities and how we handle coordinated disclosure.
Report a vulnerability
Email security@mexicanstartups.com with affected URL, reproduction steps, impact, and proof-of-concept details.
Coordinated disclosure
We acknowledge reports within 3 working days and provide regular updates until mitigation is complete. Please avoid public disclosure until remediation is deployed.
Safe testing expectations
Do not run destructive scans, social engineering, data exfiltration, or service degradation tests. Use non-invasive, good-faith research only.
Acknowledgments
With permission, we acknowledge verified reports after remediation.
Encryption
PGP key publication is pending. Please use security@mexicanstartups.com for initial contact.