TeamMidnite Security
Security Policy
We welcome responsible reports about security weaknesses affecting TeamMidnite-owned websites and services.
How to report a security issue
Use the TeamMidnite contact form. Include the affected URL or service, a clear description, reproduction steps or a minimal proof of concept, relevant timestamps or screenshots, and your preferred contact method.
Do not include passwords, access tokens, private keys, personal data, or other secrets. Redact sensitive values before sending them.
Testing boundaries
Only test TeamMidnite-owned assets that are clearly in scope. Do not test third-party services, community members, or systems you do not own or have explicit permission to assess.
- No denial-of-service, load, stress, or resource-exhaustion testing.
- No brute-force, credential stuffing, phishing, impersonation, or social engineering.
- Do not access, copy, alter, delete, or disclose data that does not belong to you.
- Do not modify production data, disrupt services, or deploy malware.
- Do not scan aggressively or in a way that creates operational impact.
Stop once you have enough evidence to explain the issue. If sensitive data is exposed, do not download or share it; report what was exposed and delete any accidental local copy.
Honeypot and monitoring notice
TeamMidnite operates security monitoring and honeypot controls. Requests to monitored endpoints may be logged for security, abuse prevention, and incident response. Logs may include timestamps, source or forwarded IP information, requested paths and queries, user-agent and referrer data, request metadata, and security classifications.
The honeypot is not permission to probe, evade monitoring, or access collected telemetry. Monitoring data is private and must not be sought, downloaded, or disclosed.
Bug bounty and compensation
TeamMidnite does not operate a paid bug-bounty program and does not offer monetary compensation, gifts, employment, credits, or other rewards unless TeamMidnite agrees to that arrangement in writing before testing.
Submitting a report does not create a contract, guarantee a response, or guarantee a fix. Useful reports may be acknowledged at TeamMidnite’s discretion.
Good-faith reporting
Reports should be made in good faith and within these boundaries. This policy is not a grant of authorization to access systems or data. TeamMidnite may investigate activity that appears abusive, unauthorized, destructive, or outside scope.