MONDO

VERIFYING ENVIRONMENT

Command Palette

Search for a command to run...

Skip to content
Mondo logoMONDO

MondoSecurity

Responsible Disclosure

Last updated — January 2026

1 min read

Ref MD-RDS-01

Mondo welcomes responsible reports from security researchers who identify potential security issues related to Mondo systems.

01Our Commitment#

We believe coordinated disclosure makes everyone safer. If you believe you have found a security issue in a Mondo system, we want to hear from you.

We will handle your report with care, investigate it seriously, and keep you informed as our work progresses.

02Reporting#

Send reports to [email protected]. Please include enough detail for us to understand and reproduce the issue. We aim to acknowledge reports promptly.

Recommended report information:

  • A description of the vulnerability.
  • The affected component (URL, page, or system).
  • Steps to reproduce the issue.
  • The potential impact as you understand it.
  • Supporting screenshots or technical details.

03Research Guidelines#

When researching Mondo systems, we ask that you:

  • Avoid accessing private user information.
  • Avoid disrupting services.
  • Avoid destructive testing.
  • Provide reasonable time for investigation before any public disclosure.
  • Communicate vulnerabilities privately before public disclosure.

04Scope#

This policy covers Mondo's web presence, including usemondo.pro, and systems operated by Mondo. Issues in third-party services we link to, social-engineering attempts, and reports without realistic security impact fall outside its scope.

Mondo does not currently operate a paid bug bounty program. Reports are reviewed and handled directly by the team.

05Safe Harbor#

If you research in good faith, respect privacy, avoid degrading our services, and follow the guidelines above, we will consider your activity to have been conducted in good faith and will not pursue legal action related to that research.

We ask in return that you give us reasonable time to investigate and address issues before any public disclosure.

06Contact#

Security reports and questions can be sent to [email protected]. Please include the word “security” in the subject line where possible.

Contact

Questions about this document? Contact us at [email protected].

End of document — MD-RDS-01