Report Security Issues
Security Vulnerability Disclosure & Bug Bounty Policy
If you’ve found a security vulnerability on maisonmansil.com, we encourage you to contact us immediately. We review legitimate security reports and aim to address valid issues as quickly as reasonably possible.
Before reporting a vulnerability, please review this document, including our fundamentals, bounty program, reward guidelines, and non-reportable issues.
Fundamentals
If you follow the principles below when reporting a security issue to Maison Mansil, we will not initiate legal action or enforcement investigations against you in response to your report, provided your activities remain within the boundaries described below.
We ask that you:
- Give us reasonable time to review and address the issue before disclosing it publicly or sharing it with others.
- Do not interact with or access private accounts without the account owner’s consent.
- Make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
- Do not exploit the vulnerability beyond what is reasonably necessary to demonstrate the issue, and do not access, modify, or exfiltrate sensitive data.
- Comply with all applicable laws and regulations.
Bounty Program
We recognize security researchers who help protect Maison Mansil by responsibly reporting security vulnerabilities. Bounties may be awarded at Maison Mansil’s discretion based on the risk, impact, exploitability, and quality of the report.
To potentially qualify for a bounty, you must:
- Follow the fundamentals listed above.
- Report a valid security vulnerability that poses a meaningful risk to privacy or security.
- Submit your report through the appropriate security contact channel rather than contacting employees directly.
- Disclose any accidental privacy violations, data exposure, or service disruptions in your report.
- Understand that while we review valid reports, priority is based on risk and impact, and a response may take some time.
- Understand that Maison Mansil reserves the right to publish or otherwise use submitted reports where legally and reasonably appropriate, while taking reasonable steps to protect sensitive information.
Rewards
Rewards are based on the impact and severity of the reported vulnerability. Please provide detailed, clear, and reproducible steps in your report. If the issue cannot be reproduced or sufficiently verified, it may not be eligible for a bounty.
- The first valid report of a previously unknown issue may receive the applicable bounty.
- Multiple bugs caused by a single underlying vulnerability may be treated as one report.
- We assess rewards based on impact, exploitability, affected systems, and report quality.
Maximum Reward Amounts by Severity
Critical Severity — Up to $200
Examples may include:
- Remote Code Execution
- Remote Shell or Command Execution
- Vertical Authentication Bypass
- SQL Injection resulting in unauthorized access to targeted data
- Full account takeover or equivalent access
High Severity — Up to $100
Examples may include:
- Lateral Authentication Bypass
- Disclosure of sensitive internal data
- Stored XSS affecting other users
- Local File Inclusion
- Insecure handling of authentication cookies
Medium Severity — Up to $50
Examples may include:
- Logic or business process vulnerabilities
- Insecure Direct Object References (IDOR)
Low Severity — Recognition Only
Examples may include:
- Open Redirects
- Reflected XSS
- Low-sensitivity information disclosure
Contact Information
📍 Address: 158 High St SE, Albuquerque, NM 87102, United States
✆ Phone: +1 (307) 400-8375
✉ Email: support@maisonasil.com
🌐 Website: https://www.maisonmansil.com