MKP IT Solutions values responsible security research. If you believe you have identified a security issue affecting this public website or an MKP-managed system that you are authorised to test, please report it privately so we can assess it.
1. How to report
Email [email protected] with the subject Security Disclosure. Include the affected URL or component, a clear description, reproduction steps and potential impact. Avoid including unnecessary personal data or sensitive information.
2. Good-faith expectations
- Make a reasonable effort to avoid privacy violations, data destruction and service disruption.
- Access only the minimum information necessary to demonstrate the issue.
- Do not exploit a vulnerability beyond what is required to confirm it.
- Keep details confidential while we investigate and coordinate remediation.
3. Activities not authorised
This policy does not authorise denial-of-service activity, social engineering, phishing, physical attacks, malware deployment, destructive testing, credential attacks, high-volume automated scanning that degrades service, or testing of third-party systems without their permission.
4. Customer and third-party environments
Do not test customer systems, production applications, third-party infrastructure or services merely because MKP IT Solutions has worked with or integrated them. Authorisation must come from the relevant system owner.
5. What happens after a report
We aim to acknowledge useful reports and assess them based on severity, reproducibility and affected scope. Remediation timing can vary. Please allow reasonable time for investigation and correction before public disclosure.
6. No bounty commitment
Unless separately agreed in writing, this policy does not create a bug-bounty programme, payment obligation, employment relationship or contractual entitlement to a reward.
7. Legal scope
This page expresses our preferred process for good-faith reporting; it is not permission to access systems without authorisation and does not waive rights or obligations under applicable law.
If an issue could expose data or materially affect security, please do not post technical details publicly before we have had a reasonable opportunity to investigate.
