Security
Report a vulnerability.
We welcome reports from security researchers. If you've found a vulnerability in a Meilynx system, here's how to reach us, what's in scope, and our commitment to researchers acting in good faith.
Tell us what you found.
One inbox, monitored by our security team. Clear reports get faster fixes.
Email security@meilynx.com
Give us time to fix it
Act in good faith
Good-faith research is authorized.
We won't penalize researchers who play by the rules.
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, will not pursue or support legal action against you, and will work with you to understand and resolve the issue promptly. If a third party brings legal action against you for activity that complied with this policy, we will make this authorization known. This policy does not authorize actions that violate applicable law.
Where to look, and where not to.
Raw prompts and responses stay inside the customer's perimeter, and each customer's managed proxy is a dedicated, single-tenant instance that never shares infrastructure with another tenant. The proxy is the asset we care most about.
In scope
- www.meilynx.com and app.meilynx.com
- The Meilynx proxy and control-plane APIs
- Authentication, authorization, and tenant-isolation flows
Out of scope
- Volumetric or denial-of-service testing of any kind
- Social engineering, phishing, or physical attacks against Meilynx or its staff
- Third-party platforms we use (e.g. our hosted Trust Center provider); report those to the relevant vendor
- Findings from automated scanners without a demonstrated, exploitable impact
We don't only wait for reports.
Researcher disclosures complement testing we commission ourselves.
Meilynx completed an independent, authenticated (Tier 2) penetration test of the Meilynx proxy in August 2026. No critical or high-severity findings were identified; the medium-severity finding was remediated and verified in retest. The full report is available under NDA through our Trust Center.
How we respond.
Acknowledgement
Within 3 business days
Resolution
Triage & fix
Recognition
Credit, not bounty
Looking for our security posture?
Live control status, our SOC 2 posture, and NDA-gated reports live in our Trust Center.