PolitiMind — Your Political Intelligence Engine

    Responsible Disclosure

    Last updated:

    1.Responsible Disclosure

    PolitiMind welcomes security research conducted in good faith. This policy describes how to report vulnerabilities and the safe-harbor we extend to compliant researchers.

    2.Scope

    • politimind.com and *.politimind.com
    • The PolitiMind application and authenticated APIs
    • $PMIND token and NFT-ballot smart contracts deployed by PolitiMind on Base (Coinbase L2)
    • PolitiMind-operated edge functions and infrastructure

    3.Out of Scope

    • Social-engineering, phishing, or physical attacks on staff or facilities
    • Third-party services (Supabase, Base, HubSpot, Contentful, Sentry) — report to those vendors directly
    • Denial-of-service testing
    • Automated scanning generating excessive load

    4.Rules of Engagement

    • Do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the issue.
    • Do not violate user privacy or disrupt the Services.
    • Do not publicly disclose before we have had a reasonable opportunity to remediate (90 days, or by agreement).
    • Use a test account when possible; never use production data of others.

    5.Safe Harbor

    PolitiMind will not pursue civil or criminal action against researchers who, in good faith, comply with this policy. We will work with you to clarify ambiguity and, where applicable, request prosecutors and platforms treat your activity as authorized.

    6.How to Report

    Email chris@politimind.com with reproduction steps, impact, and any proof-of-concept. PGP key available on request. We aim to acknowledge within 2 business days.

    This document is provided as initial v1 policy language and does not constitute legal advice. For questions, contact chris@politimind.com.