Security Policy
Last updated: June 2026
Reporting a Vulnerability
If you discover a security vulnerability on ManCore, we ask that you report it to us responsibly. Please email security@mancore.net with the following information:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact if exploited
- Any relevant screenshots or proof-of-concept (no destructive testing)
Our Commitment
- We will acknowledge your report within 48 hours
- We will investigate and provide a resolution timeline within 7 days
- We will notify you when the issue is resolved
- We will credit you in our acknowledgements if you wish
Scope
In scope for reporting:
- mancore.net and www.mancore.net
- Authentication and session management
- Data exposure or privacy issues
- XSS, CSRF, SQL injection, or similar web vulnerabilities
Out of scope:
- Denial of service attacks
- Social engineering of ManCore staff
- Physical security issues
- Issues requiring unlikely user interaction
Safe Harbour
We will not take legal action against researchers who discover and report vulnerabilities in good faith, following this policy. We ask that you do not access, modify, or delete user data, and that you stop testing once you have confirmed the vulnerability.
Contact
Email: security@mancore.net
Response time: within 48 hours