Security Policy

How to report vulnerabilities and how we handle coordinated disclosure.

Report a vulnerability

Email security@mexicanstartups.com with affected URL, reproduction steps, impact, and proof-of-concept details.

Coordinated disclosure

We acknowledge reports within 3 working days and provide regular updates until mitigation is complete. Please avoid public disclosure until remediation is deployed.

Safe testing expectations

Do not run destructive scans, social engineering, data exfiltration, or service degradation tests. Use non-invasive, good-faith research only.

Acknowledgments

With permission, we acknowledge verified reports after remediation.

Encryption

PGP key publication is pending. Please use security@mexicanstartups.com for initial contact.