1. Our Commitment
Security research makes the systems we run safer, and we welcome it. This policy explains what is in scope, how to report a vulnerability to us, what you can expect from us, and the rules that keep research safe and lawful. It covers good-faith security research only. It is not an invitation to access personal data, disrupt services, or test systems that belong to someone else.
2. Scope
In scope: the website at midgardlabs.io, including every page and file served from that domain, its DNS and email configuration, and the hosting and deployment configuration we control.
Out of scope: the platforms our providers operate, including Vercel, Google Workspace, and Google Calendar, which have their own disclosure programs (report platform issues to them directly); the Midgard Layer 2 protocol, its repositories, test networks, and its website at midgardprotocol.io, which have a separate policy; systems belonging to our clients, including any code we have reviewed or are reviewing; social engineering, phishing, or physical attacks against our team; denial-of-service, volumetric, or automated high-rate testing against any live system; and any system not listed as in scope.
This policy does not create a bug bounty. Any reward program, if we publish one, will carry its own scope, rules, and terms.
3. How to Report
Email security@midgardlabs.io. Include a description of the issue and its impact; the affected URL, component, or configuration; reproduction steps or a proof of concept; and how we can reach you for follow-up. If the report is sensitive, ask us for an encrypted channel before sending details and we will provide one.
Please give us a reasonable opportunity to fix the issue before any public disclosure and coordinate timing with us. Our default coordination window is 90 days from our acknowledgment, extendable by agreement for issues that depend on a third party.
4. What You Can Expect From Us
We will acknowledge your report within three business days, tell you whether we can reproduce the issue, keep you informed of progress, fix confirmed issues as quickly as their severity warrants, and credit you in any public note about the fix if you want credit. We will not share your report or your identity with anyone outside Midgard Labs and our providers except as needed to fix the issue or as required by law. This policy does not create any obligation to pay for a report.
5. Safe Harbor and Rules
We will not pursue or support legal action against you for good-faith security research that follows this policy, and we consider such research authorized under the Computer Fraud and Abuse Act, the Digital Millennium Copyright Act anti-circumvention provisions, and similar laws to the extent we can grant that authorization. If a third party starts legal action against you for research that followed this policy, we will make it known that your research was authorized.
To stay within this safe harbor: act in good faith and avoid privacy violations, data destruction, and service degradation; access, copy, or retain only the minimum data needed to demonstrate the issue, and never deliberately access another person’s data; stop and report immediately if you encounter personal data, credentials, or client material; do not exploit a finding beyond what is needed to demonstrate it; do not test out-of-scope systems; do not use automated tools at a rate that could disrupt the Site; and comply with applicable law. We cannot authorize research against third-party systems, and this safe harbor does not bind third parties or authorities.
6. Contact and Changes
Security contact: security@midgardlabs.io. Machine-readable contact details are published at https://midgardlabs.io/.well-known/security.txt. Reports are handled under our Privacy Policy. We may update this policy from time to time; the effective date and version will change accordingly.
