Security Disclosure
Mythos Systems welcomes responsible disclosure of security issues affecting mythossystems.net and related public services.
Scope
This policy covers mythossystems.net, the public contact channel for the site, and other Mythos Systems properties explicitly listed here or in /.well-known/security.txt.
Private repositories, unreleased products, and third-party services outside Mythos Systems control are outside default scope unless Mythos Systems asks for review.
Contact
Email security@mythossystems.net or use the contact form with category Security Disclosure.
Include the affected page or component, a clear description, reproduction steps, impact assessment, and safe contact details. Do not include live exploit payloads, credentials, or unrelated personal data in the first message.
Good-Faith Research
Good-faith research that avoids privacy violations, service disruption, data destruction, and access to unrelated systems will be reviewed without a presumption of malice.
This is not a bug-bounty program and does not authorize testing beyond the stated scope.
Out of Scope
Social engineering, physical attacks, denial-of-service against production infrastructure, attacks on third-party providers, and issues in private systems not linked from public properties are out of scope.
Response
Mythos Systems aims to acknowledge actionable reports and provide status updates as remediation proceeds. Formal service-level targets may be published after operational readiness review. No guarantee of response time is made in this draft.
Encryption
A PGP key may be published on this page when operational security review is complete. Until then, use the contact channels above without attaching exploit code.