Updated
Security Policy
July 24, 2026
MasterSteps values the work of security researchers who help us protect our website, services, and community. This policy explains how to report a potential vulnerability and the conditions for good-faith security research.
Reporting a vulnerability
Email security@mastersteps.com with the subject Security vulnerability report. Include:
- The affected URL, feature, or service.
- A clear description of the issue and its potential impact.
- Reproduction steps or a minimal proof of concept.
- Any conditions needed to reproduce the issue.
- A way to contact you if follow-up is required.
Do not include personal information, credentials, or other sensitive data unless it is necessary to explain the issue. Our machine-readable reporting information is available in security.txt.
Scope
This policy covers mastersteps.com, its official subdomains, and public web services operated by MasterSteps.
Third-party services are governed by their own security policies. You may still contact us when a vulnerability in a third-party integration directly affects MasterSteps.
Good-faith security research
When investigating a potential vulnerability:
- Follow applicable laws and this policy.
- Use only accounts and data that belong to you or that you have permission to use.
- Access only the minimum information needed to confirm the issue.
- Stop testing and report the issue if you encounter personal, confidential, or financial information.
- Do not retain, share, alter, or delete data obtained during testing.
- Avoid disrupting services or degrading their availability.
Social engineering, phishing, physical attacks, denial-of-service testing, spam, malware distribution, and high-volume automated scanning are not permitted.
Safe harbor
If you act in good faith and follow this policy, MasterSteps will not initiate legal action against you solely for your security research. If your activities raise concerns, contact us before continuing so we can clarify whether they fall within this policy.
This safe harbor does not authorize activity against third-party systems or excuse violations of applicable law.
Our response
We will review reports and may contact you for additional information. When a vulnerability is confirmed, we will work to assess and address the risk and coordinate disclosure when appropriate.
Response and remediation times depend on the severity, complexity, and services involved. This policy does not guarantee a particular response or resolution time.
Coordinated disclosure
Please give us a reasonable opportunity to investigate and address a reported vulnerability before publishing details. Coordinate public disclosure with us to reduce risk to users and services.
Recognition and rewards
MasterSteps does not currently operate a bug bounty program. Reports are not eligible for payment unless a reward was agreed to in writing before the research began.
Changes to this policy
We may update this policy as our services and security practices evolve. The current version and updated date will remain available on this page.
Contact
For security reports or questions about this policy, email security@mastersteps.com.