Report security issues through a clear, bounded process.
Security reports are welcome when they are submitted in good faith, avoid user data access, and give ChimeraMind time to investigate before public disclosure.
Send reports to [email protected] with affected URL, reproduction steps, and impact.
Good-faith testing that follows scope and avoids data harm will not trigger legal action from ChimeraMind.
Initial triage target is 3 business days. Critical reports receive priority handling.
The production web app, authenticated portal, public API routes, billing return flow, and desktop authentication handoff are in scope.
Do not perform destructive testing, social engineering, spam, denial-of-service, credential stuffing, or attempts to access third-party accounts.
Need general support?
Use the support channels page for non-security requests.