Vulnerability DisclosureCHIMERA / SECURITY DISCLOSURE
01Vulnerability Disclosure

Report security issues through a clear, bounded process.

Security reports are welcome when they are submitted in good faith, avoid user data access, and give ChimeraMind time to investigate before public disclosure.

02Contact

Send reports to [email protected] with affected URL, reproduction steps, and impact.

03Safe Harbor

Good-faith testing that follows scope and avoids data harm will not trigger legal action from ChimeraMind.

04Response SLA

Initial triage target is 3 business days. Critical reports receive priority handling.

05In scope

The production web app, authenticated portal, public API routes, billing return flow, and desktop authentication handoff are in scope.

Authentication bypass
Cross-site scripting
Access-control bugs
Sensitive data exposure
Payment or webhook validation issues
06Out of scope

Do not perform destructive testing, social engineering, spam, denial-of-service, credential stuffing, or attempts to access third-party accounts.

CTANext Step

Need general support?

Use the support channels page for non-security requests.