mashin, Inc. takes the security of our products, services, and our customers’ data seriously. We welcome and appreciate responsible security research from the security community. This policy describes how to report security vulnerabilities, how we respond, and the protections we provide to good-faith researchers.
1. Scope
1.1 In Scope
This policy covers security vulnerabilities in the following mashin, Inc. products and services:
- mashin cloud platform and all associated APIs
- mashin desktop application (Koda), all supported platforms
- mashin package registry (Kura) and associated APIs
- mashin, Inc.’s public-facing websites and web applications
- Official client libraries, SDKs, and CLI tools
- Authentication and authorization systems
- Data storage and processing infrastructure
1.2 Out of Scope
The following are outside the scope of this policy:
- Third-party applications, integrations, or services that interoperate with mashin, Inc.’s products (report to the respective vendor)
- Third-party AI model provider vulnerabilities (report directly to Anthropic, OpenAI, or the relevant provider)
- Social engineering, phishing, or physical attacks against mashin, Inc. employees, offices, or contractors
- Denial-of-service vulnerabilities (unless they reveal a deeper architectural flaw, such as an unauthenticated resource exhaustion vector)
- Issues in third-party dependencies where we are not the upstream maintainer (report to the upstream project; notify us if the dependency is used in our products)
- Vulnerabilities in products that have reached end of life
2. Reporting a Vulnerability
2.1 How to Report
Please report security vulnerabilities via email to:
Encryption: We accept PGP/GPG-encrypted reports. Our public key is published at our website under /.well-known/security.txt and on major keyservers. Key fingerprint is published alongside.
2.2 What to Include
To help us understand and reproduce the issue, please include:
- Description: A clear description of the vulnerability, the affected component, and the potential impact
- Reproduction steps: Detailed steps to reproduce the vulnerability, including any prerequisites
- Affected product and version: Which product, version, and platform are affected
- Proof of concept: Code, screenshots, or video demonstrating the vulnerability, where applicable
- Impact assessment: Your assessment of the severity and potential impact
- Your contact information: So we can follow up with questions and status updates
2.3 Responsible Conduct
When researching and reporting vulnerabilities, please:
- Do not access, modify, delete, or exfiltrate data belonging to other users or customers
- Do not perform testing that degrades service quality or availability for other users
- Do not use automated vulnerability scanners against production systems without prior written authorization
- Do not disclose the vulnerability publicly until we have had reasonable time to address it and have coordinated disclosure with you
- Do limit your testing to the minimum necessary to demonstrate the vulnerability
- Do report the vulnerability to us before disclosing to any other party
- Do delete any mashin, Inc. data you accessed during your research as soon as it is no longer needed
3. Our Response
3.1 Response Timeline
We commit to the following response timelines:
| Stage | Target Timeline |
|---|---|
| Acknowledgment of your report | Within 2 business days |
| Initial triage and severity assessment | Within 5 business days |
| Status update to reporter | At least every 10 business days until resolution |
| Fix for Critical severity | 7 calendar days from confirmation |
| Fix for High severity | 30 calendar days from confirmation |
| Fix for Medium severity | 90 calendar days from confirmation |
| Fix for Low severity | Next scheduled release |
These are target timelines. Some vulnerabilities, particularly those involving complex architectural changes or third-party dependencies, may require additional time. We will communicate expected timelines and any delays transparently.
3.2 Severity Classification
We classify vulnerability severity using CVSS v3.1 base scores:
| Severity | CVSS Score | Examples |
|---|---|---|
| Critical | 9.0 - 10.0 | Remote code execution, authentication bypass, full data exposure |
| High | 7.0 - 8.9 | Privilege escalation, significant data leakage, stored XSS |
| Medium | 4.0 - 6.9 | CSRF, information disclosure of limited data, reflected XSS |
| Low | 0.1 - 3.9 | Minor information disclosure, UI redressing, low-impact issues |
3.3 Communication
We will keep you informed of our progress at each stage. All communications will be via the email address you provide in your report (encrypted with your PGP key if you provided one). We will not share your identity or contact information without your consent.
4. Safe Harbor
mashin, Inc. considers security research conducted in compliance with this policy to be:
- Authorized under the Computer Fraud and Abuse Act (CFAA) and similar laws
- Exempt from DMCA anti-circumvention provisions when conducted for the purpose of identifying vulnerabilities
- Lawful and not grounds for civil or criminal action by mashin, Inc.
We will not pursue legal action against researchers who:
- Make a good-faith effort to comply with this policy
- Report vulnerabilities directly to mashin, Inc. before any public disclosure
- Avoid privacy violations, data destruction, and service disruption
- Do not exploit vulnerabilities beyond the minimum necessary to confirm them
- Do not access, copy, or exfiltrate data belonging to other users or customers
- Act in good faith to avoid harm to mashin, Inc., our customers, and third parties
If legal action is initiated by a third party against a researcher who has complied with this policy, mashin, Inc. will take reasonable steps to make known that the researcher’s actions were conducted in compliance with this policy, including providing a written statement to the researcher’s legal counsel if requested.
5. Recognition and Rewards
5.1 Acknowledgment
With your permission, we will publicly acknowledge your contribution on our Security Acknowledgments page, including your name (or handle) and a brief description of the vulnerability category. You may choose to remain anonymous.
5.2 Bug Bounty
We do not currently operate a formal bug bounty program with monetary rewards. We may introduce a bug bounty program in the future. If and when we do, details and scope will be published on our website. Researchers who have previously reported valid vulnerabilities will be notified.
5.3 Responsible Disclosure Timeline
We follow a coordinated disclosure model. Once a vulnerability is fixed and the fix has been deployed: (a) we will coordinate with you on an appropriate public disclosure timeline, typically 90 days from the fix being available; (b) you may publish a write-up of the vulnerability after this period; and (c) we will credit you in any security advisory we publish about the vulnerability.
6. Security Practices
For information about mashin, Inc.’s security architecture, infrastructure protection, compliance certifications, and security practices, see our Trust Center on our website.
7. Contact
- Security vulnerability reports: [email protected]
- General security questions: [email protected]
- Other inquiries: [email protected]
- security.txt: Published at our website under
/.well-known/security.txtper RFC 9116
Questions? Contact mashin, Inc. at [email protected].