Vulnerability Disclosure PolicyDraft skeleton — CTO scope confirmation required
Last updated: 2026-05-19
Contents (8 sections)
Our position
If you discover a security vulnerability in any system Mens Network operates, we want to know. We will work with you in good faith to investigate and resolve it, and we will not pursue legal action against you for reporting in line with this Policy.
This is an unbounded, ongoing programme. We do not currently operate a paid bug bounty, but we acknowledge confirmed reports publicly (with your consent) and credit researchers in our Security Hall of Fame once that exists.
Scope
In scope:
- mensnetwork.global (the marketing site and the Nexus directory platform)
- *.mensnetwork.global subdomains where they are operated by Mens Network Ltd
- The Mens Network API (when published)
- Configuration of cloud infrastructure operated by Mens Network Ltd
Out of scope:
- Third-party services we use (Supabase, Railway, HubSpot, Beehiiv, Cloudflare, Zoho, etc.) — report directly to the provider; we will help coordinate if you tell us.
- Issues in our underlying Open Source dependencies that have already been disclosed upstream.
- Denial of service, brute-forcing, social engineering, or physical security tests.
- Issues that require physical access to a user's device.
- Reports of email security configuration (SPF / DKIM / DMARC) — useful to flag but generally low severity; please email rather than submitting as a vulnerability report.
- Reports generated solely from automated scanner output, with no demonstrated impact.
CTO: confirm and expand the scope lists against actual deployed infrastructure.
How to report
Preferred channel: Email security@mensnetwork.global
Include:
- A description of the vulnerability and its potential impact.
- The steps required to reproduce it (a proof-of-concept is welcome but not required).
- Any URLs, screenshots, or example payloads relevant to the issue.
- Your name and how you'd like to be credited (or "anonymous" if you prefer).
For higher-severity issues we provide a PGP key on request — email and ask.
A security.txt file is published at https://mensnetwork.global/.well-known/security.txt in line with RFC 9116. [CTO: confirm published or schedule publication.]
What we ask of you
When testing, please:
- Do not access, modify, or delete data that does not belong to you. If you find data that suggests a vulnerability has been exploited, stop and report rather than investigate further.
- Do not perform tests that could degrade the service or harm users (no DoS, no automated load testing without our written agreement).
- Do not publicly disclose the vulnerability before we have had a reasonable opportunity to fix it. We aim to fix critical issues quickly — see "Our response" below.
- Comply with the Computer Misuse Act 1990 and applicable laws.
- Stay within the scope above. If you are unsure, ask first.
Our response
When you report in line with this Policy:
| Stage | Aim |
|---|---|
| Acknowledgement | Within 2 working days |
| Triage decision (in / out of scope, severity) | Within 5 working days |
| Resolution plan | Within 15 working days for critical; longer for lower severity |
| Public disclosure (if appropriate) | After resolution, coordinated with you |
We will keep you informed as we work. We will tell you when we have fixed the issue. We will credit you publicly (with your consent).
CTO: confirm these SLA figures are achievable given current capacity. Adjust if not.
Safe harbour
Where you have made a good-faith effort to comply with this Policy:
- We will not pursue or support any legal action against you.
- We will not ask law enforcement to investigate you.
- We consider your testing authorised under the Computer Misuse Act 1990 to the extent of your scope-compliant activity.
If a third party threatens or pursues legal action against you arising from your good-faith vulnerability research conducted under this Policy, we will support you publicly.
This safe harbour does not extend to activity outside the scope or testing standards in this Policy.
Recognition
With your consent, we publicly credit researchers who report confirmed vulnerabilities. Where you prefer to remain anonymous, we respect that.
We do not currently pay bug bounties. If our position on this changes, we will update this Policy and existing reporters will be notified.
Contact
Security reports: security@mensnetwork.global
For everything else: see our Contact page