mashin, Inc. takes the security of our products, services, and our customers’ data seriously. We welcome and appreciate responsible security research from the security community. This policy describes how to report security vulnerabilities, how we respond, and the protections we provide to good-faith researchers.

1. Scope

1.1 In Scope

This policy covers security vulnerabilities in the following mashin, Inc. products and services:

  • mashin cloud platform and all associated APIs
  • mashin desktop application (Koda), all supported platforms
  • mashin package registry (Kura) and associated APIs
  • mashin, Inc.’s public-facing websites and web applications
  • Official client libraries, SDKs, and CLI tools
  • Authentication and authorization systems
  • Data storage and processing infrastructure

1.2 Out of Scope

The following are outside the scope of this policy:

  • Third-party applications, integrations, or services that interoperate with mashin, Inc.’s products (report to the respective vendor)
  • Third-party AI model provider vulnerabilities (report directly to Anthropic, OpenAI, or the relevant provider)
  • Social engineering, phishing, or physical attacks against mashin, Inc. employees, offices, or contractors
  • Denial-of-service vulnerabilities (unless they reveal a deeper architectural flaw, such as an unauthenticated resource exhaustion vector)
  • Issues in third-party dependencies where we are not the upstream maintainer (report to the upstream project; notify us if the dependency is used in our products)
  • Vulnerabilities in products that have reached end of life

2. Reporting a Vulnerability

2.1 How to Report

Please report security vulnerabilities via email to:

[email protected]

Encryption: We accept PGP/GPG-encrypted reports. Our public key is published at our website under /.well-known/security.txt and on major keyservers. Key fingerprint is published alongside.

2.2 What to Include

To help us understand and reproduce the issue, please include:

  • Description: A clear description of the vulnerability, the affected component, and the potential impact
  • Reproduction steps: Detailed steps to reproduce the vulnerability, including any prerequisites
  • Affected product and version: Which product, version, and platform are affected
  • Proof of concept: Code, screenshots, or video demonstrating the vulnerability, where applicable
  • Impact assessment: Your assessment of the severity and potential impact
  • Your contact information: So we can follow up with questions and status updates

2.3 Responsible Conduct

When researching and reporting vulnerabilities, please:

  • Do not access, modify, delete, or exfiltrate data belonging to other users or customers
  • Do not perform testing that degrades service quality or availability for other users
  • Do not use automated vulnerability scanners against production systems without prior written authorization
  • Do not disclose the vulnerability publicly until we have had reasonable time to address it and have coordinated disclosure with you
  • Do limit your testing to the minimum necessary to demonstrate the vulnerability
  • Do report the vulnerability to us before disclosing to any other party
  • Do delete any mashin, Inc. data you accessed during your research as soon as it is no longer needed

3. Our Response

3.1 Response Timeline

We commit to the following response timelines:

StageTarget Timeline
Acknowledgment of your reportWithin 2 business days
Initial triage and severity assessmentWithin 5 business days
Status update to reporterAt least every 10 business days until resolution
Fix for Critical severity7 calendar days from confirmation
Fix for High severity30 calendar days from confirmation
Fix for Medium severity90 calendar days from confirmation
Fix for Low severityNext scheduled release

These are target timelines. Some vulnerabilities, particularly those involving complex architectural changes or third-party dependencies, may require additional time. We will communicate expected timelines and any delays transparently.

3.2 Severity Classification

We classify vulnerability severity using CVSS v3.1 base scores:

SeverityCVSS ScoreExamples
Critical9.0 - 10.0Remote code execution, authentication bypass, full data exposure
High7.0 - 8.9Privilege escalation, significant data leakage, stored XSS
Medium4.0 - 6.9CSRF, information disclosure of limited data, reflected XSS
Low0.1 - 3.9Minor information disclosure, UI redressing, low-impact issues

3.3 Communication

We will keep you informed of our progress at each stage. All communications will be via the email address you provide in your report (encrypted with your PGP key if you provided one). We will not share your identity or contact information without your consent.

4. Safe Harbor

mashin, Inc. considers security research conducted in compliance with this policy to be:

  • Authorized under the Computer Fraud and Abuse Act (CFAA) and similar laws
  • Exempt from DMCA anti-circumvention provisions when conducted for the purpose of identifying vulnerabilities
  • Lawful and not grounds for civil or criminal action by mashin, Inc.

We will not pursue legal action against researchers who:

  • Make a good-faith effort to comply with this policy
  • Report vulnerabilities directly to mashin, Inc. before any public disclosure
  • Avoid privacy violations, data destruction, and service disruption
  • Do not exploit vulnerabilities beyond the minimum necessary to confirm them
  • Do not access, copy, or exfiltrate data belonging to other users or customers
  • Act in good faith to avoid harm to mashin, Inc., our customers, and third parties

If legal action is initiated by a third party against a researcher who has complied with this policy, mashin, Inc. will take reasonable steps to make known that the researcher’s actions were conducted in compliance with this policy, including providing a written statement to the researcher’s legal counsel if requested.

5. Recognition and Rewards

5.1 Acknowledgment

With your permission, we will publicly acknowledge your contribution on our Security Acknowledgments page, including your name (or handle) and a brief description of the vulnerability category. You may choose to remain anonymous.

5.2 Bug Bounty

We do not currently operate a formal bug bounty program with monetary rewards. We may introduce a bug bounty program in the future. If and when we do, details and scope will be published on our website. Researchers who have previously reported valid vulnerabilities will be notified.

5.3 Responsible Disclosure Timeline

We follow a coordinated disclosure model. Once a vulnerability is fixed and the fix has been deployed: (a) we will coordinate with you on an appropriate public disclosure timeline, typically 90 days from the fix being available; (b) you may publish a write-up of the vulnerability after this period; and (c) we will credit you in any security advisory we publish about the vulnerability.

6. Security Practices

For information about mashin, Inc.’s security architecture, infrastructure protection, compliance certifications, and security practices, see our Trust Center on our website.

7. Contact


Questions? Contact mashin, Inc. at [email protected].