Responsible security reporting
MTera welcomes careful reports about security issues affecting mtera.eu. Until a dedicated channel is approved, use privacy@mtera.eu with a clear security-report subject.
Last updated
What to send
Include the affected URL, a concise description, reproducible steps that avoid harm, observed and expected behaviour, and a safe way to contact you. Redact personal data and credentials.
What not to send or do
Do not send secrets in ordinary email, access or alter other people's data, disrupt availability, use destructive testing, persist after demonstrating the issue or disclose details before a response path is agreed.
Scope and authorisation
This page does not grant broad testing authorisation or define a bug-bounty programme. Stop if testing may affect data, users or service availability and ask for a safe route.
Response expectations
No fixed response or remediation time is promised until an operational security process is approved. Acknowledgement and coordination details should be communicated based on severity and available evidence.
Information minimisation
Public guidance intentionally does not disclose infrastructure details that could increase risk.