Vulnerability Disclosure program

Vulnerability Disclosure Program

Last updated: July 31, 2026

1. Overview

Manatal values the work of security researchers and supports responsible, coordinated vulnerability disclosure to help protect our customers, users, and platform.

This page explains how external security researchers can report potential vulnerabilities to Manatal, which assets are in scope, and what to expect during our review process.

2. How to Submit a Vulnerability Report

Security researchers should submit vulnerability reports through Manatal’s official vulnerability disclosure channel.

Current submission channel: Vulnerability Disclosure Portal

3. Scope

The current vulnerability disclosure scope is limited to the following exact in-scope assets:

3.1 In-Scope

Only the exact assets listed above are in scope. Wildcard subdomains such as *.manatal.com are not included.

3.2 Out-of-Scope

The following third-party-hosted or branded Manatal assets are out of scope:

Reports affecting assets outside the listed in-scope assets may not be eligible for review or reward.

Manatal may update the scope at any time.

3.3 Out-of-Scope Vulnerability Types

The following vulnerability types are generally considered out of scope and may not be eligible for review or reward unless a clear, practical security impact is demonstrated:

  • Raw automated scanner output without validation or reproduction steps.
  • SPF, DKIM, DMARC, or other email configuration issues.
  • Missing security headers.
  • Clickjacking without demonstrated impact.
  • Self-XSS without impact to other users.
  • Version disclosure without demonstrated security impact.
  • Logout CSRF without meaningful security impact.

Reports in these categories may be closed without reward if no clear, practical security impact is demonstrated.

4. Required Report Information

To help us review your report efficiently, please include:

  • Vulnerability title
  • Summary of the issue
  • Affected URL, endpoint, or feature
  • Steps to reproduce
  • Proof of Concept, such as screenshots, screen recordings, logs, or request/response samples
  • Security impact

Reports that do not include enough information to validate the issue may be closed or may require additional clarification.

Please avoid including real user data, customer data, or sensitive third-party information in your report.

5. Review Process and Expected Communication

After a report is submitted, Manatal will review it to determine whether it is complete, reproducible, in scope, and eligible for further action.

Manatal’s review and communication process generally follows the expectations below:

  • Manatal aims to acknowledge receipt of submitted vulnerability reports within 5 business days.
  • Manatal may contact you if additional information is required, if the report status changes, or when there is a meaningful update regarding the report.
  • To reduce unnecessary back-and-forth, please avoid repeated status requests while the report is under review.
  • Repeated follow-up messages without new technical information may not receive a separate response.

6. Reward Eligibility

Eligible reports may qualify for a reward based on severity, impact, exploitability, report quality, and whether the issue was previously known to Manatal.

Reward decisions are made at Manatal’s discretion after validation of the report.

The following reports may not be eligible for a reward:

  • Duplicate reports
  • Out-of-scope reports
  • Reports without a demonstrated security impact
  • Reports that cannot be reproduced
  • Previously known issues
  • Reports that violate this policy or the Rules of Engagement

Submitting a report does not guarantee a reward.

7. Rules of Engagement

When testing and reporting vulnerabilities to Manatal, you must follow responsible testing practices.

You must:

  • Test only against assets listed in scope.
  • Test only against accounts you own, such as your own Manatal free trial account. Never test against customer accounts or customer data.
  • Keep vulnerability details confidential and do not disclose them publicly without Manatal’s written approval.
  • Do not access, copy, download, transfer, disclose, modify, or delete data that does not belong to you.
  • Stop testing immediately and notify Manatal if you accidentally access sensitive data or cause any impact to system availability.

You must not perform:

  • Social engineering, phishing, or attacks against Manatal employees, customers, or users.
  • Denial-of-service, distributed denial-of-service, resource exhaustion, or disruptive automated testing.
  • Testing that may damage, interrupt, degrade, or negatively affect Manatal services.
  • Accessing, copying, downloading, transferring, disclosing, modifying, or deleting customer, user, employee, or third-party data without authorization.
  • Public disclosure of vulnerability details before Manatal has completed its review and remediation process.

Manatal reserves the right to reject reports that violate these rules.

8. Safe Harbor

Manatal will not pursue legal action against security researchers who act in good faith, report vulnerabilities through the official vulnerability disclosure channel, and comply with this policy’s scope and Rules of Engagement.

To remain eligible for safe harbor, you must avoid accessing, copying, downloading, modifying, deleting, or disclosing data that does not belong to you, avoid disrupting Manatal services, and keep vulnerability details confidential unless Manatal provides written approval for disclosure.

Safe harbor does not apply to activity that violates this policy, causes harm to Manatal or its users, affects service availability, accesses or exposes data without authorization, or involves unlawful activity.

Manatal reserves the right to evaluate whether a researcher’s activity qualifies for safe harbor based on the facts and circumstances of each case.

Try Manatal for free during 14-day with no commitment.

No credit card required
No commitment
Try it Now