Public posture
The static product surface uses Cloudflare Pages security headers and publishes a canonical security.txt contact route.
Request accessSECURITY
Blackbox security material separates public posture, vulnerability reporting and explicitly authorized active testing.
The static product surface uses Cloudflare Pages security headers and publishes a canonical security.txt contact route.
Suspected vulnerabilities can be reported to security@mediatorsolutions.io. A report does not authorize active testing.
Testing requires written scope, target authority, permitted methods, stop conditions, evidence handling and Rules of Engagement.
Findings preserve reproduction conditions and a bounded retest path rather than implying certification.