Security & Vulnerability
// THE COMMUNITY // EFFECTIVE DATE: JUNE 20, 2026
We are committed to maintaining a robust, secure infrastructure. Read these guidelines to report findings responsibly under safe-harbor terms.
// 1. Security Commitment
Security and data confidentiality represent critical components of **THE COMMUNITY** (operating under **Mindblowing Jobs**). We implement continuous monitoring, cryptographic auth gateways, and standard network layers to isolate and shield our user logs.
We value the input of independent security researchers and white-hat developers. If you identify a bug or architectural vulnerability within the Platform, we invite you to report it privately through our disclosure program.
// 2. Reporting Vulnerabilities
To file a vulnerability report, please send an email to our security division with the details. Your notice should contain:
- A clear description of the vulnerability, including affected endpoints, APIs, or parameters.
- Detailed, step-by-step instructions to reproduce the issue (including proof-of-concept scripts or request payloads if applicable).
- A description of the potential impact (e.g. SQL injection, privilege escalation, cross-site scripting).
Please avoid attaching screenshots or log archives containing PII or sensitive credentials belonging to other platform members.
// 3. Safe Harbor Terms
Mindblowing Jobs will not initiate civil actions or request law enforcement investigations against researchers who conduct security research and submit reports in accordance with these guidelines.
To remain eligible for safe harbor, you must:
- Refrain from accessing, copying, deleting, or altering data belonging to real platform users.
- Provide us a reasonable duration of time to remediate findings before releasing any information to the public.
- Avoid performing denial-of-service (DoS) or brute-force tests.
// 4. Out of Scope Testing
The following research vectors are strictly out-of-scope and not covered under our safe-harbor terms:
- Social engineering, phishing, or physical intrusion attacks against Mindblowing Jobs headquarters, staff, or contractors.
- Application denial-of-service testing (e.g., flooding requests or resource exhaustion).
- Automated scanner spamming that generates thousands of requests without targeted proof-of-concepts.
// 5. Security Contact
All security notices, vulnerability reports, or queries concerning data isolation must be dispatched to:
// CONTACT: Mindblowing Jobs security division
// EMAIL: support@mindblowingjobs.com
// STATUS: Active response desk
