Responsible security reporting
MTera welcomes careful reports about security issues affecting mtera.eu. Until a dedicated channel is approved, use privacy@mtera.eu with a subject line that clearly identifies the message as a security report.
Last updated
What to send
Include the affected URL, a concise description, reproducible steps that avoid harm, observed and expected behavior, and a safe way to contact you. Redact personal data and credentials.
What not to send or do
Do not send secrets in ordinary email, access or alter other people's data, disrupt availability, use destructive testing, persist after demonstrating the issue or disclose details before a response path is agreed.
Scope and authorization
This page does not grant broad testing authorization or define a bug-bounty program. Stop if testing may affect data, users or service availability and ask for a safe reporting path.
Response expectations
No fixed response or remediation time is promised until an operational security process is approved. Acknowledgment and coordination details should be communicated based on severity and available evidence.
Information minimization
Public guidance intentionally does not disclose infrastructure details that could increase risk.