Manatal values the work of security researchers and supports responsible, coordinated vulnerability disclosure to help protect our customers, users, and platform.
This page explains how external security researchers can report potential vulnerabilities to Manatal, which assets are in scope, and what to expect during our review process.
Security researchers should submit vulnerability reports through Manatal’s official vulnerability disclosure channel.
Current submission channel: Vulnerability Disclosure Portal
The current vulnerability disclosure scope is limited to the following exact in-scope assets:
Only the exact assets listed above are in scope. Wildcard subdomains such as *.manatal.com are not included.
The following third-party-hosted or branded Manatal assets are out of scope:
Reports affecting assets outside the listed in-scope assets may not be eligible for review or reward.
Manatal may update the scope at any time.
The following vulnerability types are generally considered out of scope and may not be eligible for review or reward unless a clear, practical security impact is demonstrated:
Reports in these categories may be closed without reward if no clear, practical security impact is demonstrated.
To help us review your report efficiently, please include:
Reports that do not include enough information to validate the issue may be closed or may require additional clarification.
Please avoid including real user data, customer data, or sensitive third-party information in your report.
After a report is submitted, Manatal will review it to determine whether it is complete, reproducible, in scope, and eligible for further action.
Manatal’s review and communication process generally follows the expectations below:
Eligible reports may qualify for a reward based on severity, impact, exploitability, report quality, and whether the issue was previously known to Manatal.
Reward decisions are made at Manatal’s discretion after validation of the report.
The following reports may not be eligible for a reward:
Submitting a report does not guarantee a reward.
When testing and reporting vulnerabilities to Manatal, you must follow responsible testing practices.
You must:
You must not perform:
Manatal reserves the right to reject reports that violate these rules.
Manatal will not pursue legal action against security researchers who act in good faith, report vulnerabilities through the official vulnerability disclosure channel, and comply with this policy’s scope and Rules of Engagement.
To remain eligible for safe harbor, you must avoid accessing, copying, downloading, modifying, deleting, or disclosing data that does not belong to you, avoid disrupting Manatal services, and keep vulnerability details confidential unless Manatal provides written approval for disclosure.
Safe harbor does not apply to activity that violates this policy, causes harm to Manatal or its users, affects service availability, accesses or exposes data without authorization, or involves unlawful activity.
Manatal reserves the right to evaluate whether a researcher’s activity qualifies for safe harbor based on the facts and circumstances of each case.