> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mudraid.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Responsible disclosure

> How to report a security problem.

Found a security problem? Tell us before you tell the world.

## How to report

<Note>
  Set up a real reporting channel before launch: a `security@` mailbox or a `SECURITY.md` in the repo. This page is a placeholder until that's in place.
</Note>

* Email the security contact (to be published).
* Or open a private advisory on the [GitHub repo](https://github.com/Decryptellix/MudraID-Backend).

Don't open a public issue for a vulnerability.

## What to include

* What you found.
* How to reproduce it.
* What an attacker could do with it.
* Any suggested fix.

## What to expect

* An acknowledgement.
* An assessment against our [security model](/security/overview).
* A fix or a reason it's out of scope.

## Scope

Our [security model](/security/overview) sets the line. Some things are known boundaries — host side-channels, infrastructure takeover, and layer 3/4 DDoS — and won't be treated as new findings. Everything else, we want to hear about.
