# Mortar (mortarsec.com) — security contact. # # Found a vulnerability in Mortar? Please report it privately to the address # below rather than disclosing it publicly. We welcome good-faith security # research, will acknowledge your report, and will work with you on coordinated # disclosure. Please give us a reasonable window to remediate before any public # write-up. # # Out of scope: denial-of-service, volumetric/automated scanning, social # engineering of our staff or customers, and anything that accesses, modifies, # or exfiltrates real customer data (test against your own tenant only). Contact: mailto:security@mortarsec.com Expires: 2027-07-17T00:00:00.000Z Preferred-Languages: en Canonical: https://app.mortarsec.com/.well-known/security.txt