Vulnerability Disclosure Policy
MantisOps, LLC — last updated 23 July 2026
We welcome reports from security researchers. If you believe you have found a
vulnerability in MantisRMM, Mantis360, the customer portal, our agents, or any
mantisops.net service, please tell us before disclosing it publicly.
Report to security@mantisops.net
Include the affected URL or component, the steps to reproduce, and what impact you believe it has.
Please send it in English. Machine-readable contact details:
security.txt.
What we commit to
- We aim to acknowledge your report within 3 business days.
- We will tell you whether we consider it a vulnerability, and our intended fix timeline.
- We will keep you updated while we work on it, and confirm when it is resolved.
- We will credit you when we publish a fix, if you would like us to.
We are a small company and do not currently operate a paid bug-bounty programme.
What we ask of you
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
- Only test against accounts and data you own. Do not access, modify, or retain
other customers' data — if you encounter it accidentally, stop and tell us.
- Do not run denial-of-service, spam, or social-engineering tests against us,
our staff, or our customers.
- Do not test the physical security of any premises, or third-party services we use.
In scope
mantisops.net and its subdomains (rmm, 360, portal, api.*, status)
- The MantisRMM and Mantis360 agents and probes
Out of scope
- Findings that require a compromised device, rooted OS, or physical access
- Missing security headers, cookie flags, or TLS configuration with no demonstrated impact
- Automated scanner output submitted without a working proof of concept
- Rate-limiting, email-enumeration, and self-XSS reports with no realistic attack path
- Vulnerabilities in third-party services we consume, which should go to that vendor
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support
legal action against you for your research, and we will treat your report as an authorised
contribution to our security. If a third party brings action against you for activity that
complied with this policy, we will make that authorisation clear.