Vulnerability Disclosure Policy

MantisOps, LLC — last updated 23 July 2026

We welcome reports from security researchers. If you believe you have found a vulnerability in MantisRMM, Mantis360, the customer portal, our agents, or any mantisops.net service, please tell us before disclosing it publicly.

Report to security@mantisops.net
Include the affected URL or component, the steps to reproduce, and what impact you believe it has. Please send it in English. Machine-readable contact details: security.txt.

What we commit to

We are a small company and do not currently operate a paid bug-bounty programme.

What we ask of you

In scope

Out of scope

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as an authorised contribution to our security. If a third party brings action against you for activity that complied with this policy, we will make that authorisation clear.