Vulnerability disclosure
https://manymoats.com · coordinated disclosure · no bounty program (yet)
How to report
Email architect@exlegacy.com with:
- Affected URL or product face
- Clear steps to reproduce
- Impact (what an attacker could do)
- Your preferred contact for follow-up
Machine-readable contact: /.well-known/security.txt
Scope
- Production hosts we operate for this brand
- Auth, payment, data isolation, and secret-exposure findings preferred
Out of scope
- Social engineering of staff or users
- Physical attacks, DoS volume tests without prior written approval
- Third-party services we do not control (report to them when possible)
- Automated scanner output with no demonstrated impact
Our promise
- We will acknowledge good-faith reports
- We will not pursue legal action against researchers who act in good faith, avoid privacy harm, and give us a reasonable chance to fix before public disclosure
- Please do not access other users' data, destroy data, or pivot beyond what is needed to prove the issue