MOSAIC STRATA

MOSAIC STRATAMOSAIC STRATAMOSAIC STRATA
Home
Company
Technology
  • MOSAIC Auren
  • MOSAIC-OS
  • LIS
  • Trust Architecture
  • Evidence & Integrity
Solutions
Insights
Contact
Trust Center

MOSAIC STRATA

MOSAIC STRATAMOSAIC STRATAMOSAIC STRATA
Home
Company
Technology
  • MOSAIC Auren
  • MOSAIC-OS
  • LIS
  • Trust Architecture
  • Evidence & Integrity
Solutions
Insights
Contact
Trust Center
More
  • Home
  • Company
  • Technology
    • MOSAIC Auren
    • MOSAIC-OS
    • LIS
    • Trust Architecture
    • Evidence & Integrity
  • Solutions
  • Insights
  • Contact
  • Trust Center
  • Home
  • Company
  • Technology
    • MOSAIC Auren
    • MOSAIC-OS
    • LIS
    • Trust Architecture
    • Evidence & Integrity
  • Solutions
  • Insights
  • Contact
  • Trust Center

RESPONSIBLE DISCLOSURE POLICY

 

RESPONSIBLE DISCLOSURE POLICY

Effective Date: August 5, 2026

1. Our Commitment

MOSAIC Strata values the contributions of security researchers and members of the cybersecurity community who responsibly identify and report potential security vulnerabilities.

This Responsible Disclosure Policy provides guidelines for reporting security concerns involving systems that are owned and controlled by MOSAIC Strata.

Our goal is to support constructive security research, protect visitors and future customers, and address legitimate security concerns responsibly.

This policy is not a bug-bounty program. MOSAIC Strata does not currently offer monetary rewards, merchandise, compensation, employment, public recognition, or other benefits in exchange for vulnerability reports.

2. Scope

At this time, this policy applies only to:

  • The publicly accessible MOSAIC Strata website 
  • Web pages operating under the mosaic-strata.com domain 
  • Website functions that are directly owned and controlled by MOSAIC Strata 
  • Public contact forms and website content managed by MOSAIC Strata 

A system is in scope only when MOSAIC Strata has the authority to permit testing of that system.

If ownership or authorization is unclear, stop testing and contact MOSAIC Strata before continuing.

3. Systems Outside the Scope

The following are not authorized for testing under this policy:

  • GoDaddy infrastructure, accounts, hosting systems, website-builder services, or administrative interfaces 
  • LinkedIn or other third-party websites and platforms 
  • Email providers and email-delivery infrastructure 
  • Domain registrars, DNS providers, content-delivery networks, analytics providers, or security vendors 
  • Third-party applications, libraries, services, or integrations 
  • Personal accounts or devices belonging to MOSAIC Strata personnel 
  • Private development, testing, laboratory, staging, administrative, or internal systems 
  • MOSAIC Auren, MOSAIC-OS, LIS, or other software that has not been publicly released with an accompanying testing authorization 
  • Customer, partner, vendor, or contractor systems 
  • Any system that is not explicitly identified as in scope 

The presence of a MOSAIC Strata name, logo, link, account, or integration does not establish ownership or authorization to test an underlying third-party system.

Vulnerabilities affecting third-party services should be reported directly to the organization that owns or operates the affected service.

4. Authorized Research

MOSAIC Strata authorizes limited, good-faith security research involving in-scope systems when all requirements of this policy are followed.

Authorized research must:

  • Be conducted solely to identify and help correct a security vulnerability 
  • Be limited to the minimum testing necessary to confirm the issue 
  • Avoid harm to people, systems, data, availability, and business operations 
  • Avoid accessing, modifying, downloading, retaining, or disclosing data belonging to another person 
  • Stop immediately if sensitive, confidential, personal, regulated, or proprietary information is encountered 
  • Avoid degrading performance or interrupting service 
  • Use only accounts and information that belong to the researcher or for which the researcher has explicit authorization 
  • Be reported to MOSAIC Strata promptly and privately 
  • Give MOSAIC Strata a reasonable opportunity to investigate and address the issue before public disclosure 
  • Comply with applicable law 

Authorization applies only to conduct that remains within the exact boundaries of this policy.

5. Prohibited Activities

The following activities are not authorized:

  • Denial-of-service or distributed denial-of-service testing 
  • Load testing, stress testing, traffic flooding, or resource exhaustion 
  • Automated scanning that generates excessive requests or disrupts service 
  • Malware deployment 
  • Ransomware activity 
  • Destructive testing 
  • Data destruction, corruption, alteration, or deletion 
  • Accessing data beyond what is minimally necessary to confirm a vulnerability 
  • Downloading or retaining personal, confidential, proprietary, or regulated data 
  • Credential theft, credential stuffing, password spraying, or brute-force attacks 
  • Phishing, vishing, smishing, pretexting, or other social-engineering activity 
  • Testing employees, contractors, customers, partners, or visitors 
  • Physical-security testing 
  • Attempting to access offices, equipment, networks, or facilities 
  • Wireless-network testing 
  • Testing third-party systems or services 
  • Supply-chain attacks 
  • Persistence, backdoors, web shells, or command-and-control mechanisms 
  • Pivoting from an in-scope system to another system 
  • Privilege escalation beyond the minimum required to demonstrate the issue 
  • Exfiltration or public disclosure of data 
  • Extortion, threats, demands, or coercion 
  • Requesting payment as a condition of withholding information 
  • Testing intended to support unauthorized access, surveillance, espionage, cyberwarfare, fraud, or harm 
  • Violating applicable law or another party’s rights 

If testing creates instability, exposes sensitive information, or causes unintended effects, stop immediately and report the situation.

6. Sensitive Information

If you unexpectedly encounter sensitive information:

  1. Stop testing immediately. 
  2. Do not continue browsing, querying, or enumerating the data. 
  3. Do not download, copy, photograph, retain, transmit, or share the information. 
  4. Record only the minimum information needed to explain where the exposure occurred. 
  5. Notify MOSAIC Strata promptly. 
  6. Delete any unintentionally retained information after MOSAIC Strata confirms that it is no longer needed for validation. 

Do not include sensitive information directly in an initial report submitted through the general website contact form.

7. How to Submit a Report

To initiate a security report, use the MOSAIC Strata Contact page.

Clearly begin the message with:

RESPONSIBLE DISCLOSURE REPORT

The initial message should include:

  • Your name or preferred identifier 
  • A reliable contact method 
  • The affected page or in-scope asset 
  • A concise description of the suspected vulnerability 
  • The date and approximate time of discovery 
  • Whether sensitive information may have been exposed 
  • Whether any unexpected system impact occurred 
  • A request for a secure communication method if detailed evidence is required 

Do not submit through the general contact form:

  • Passwords 
  • Authentication tokens 
  • Private keys 
  • Personal information 
  • Customer data 
  • Proprietary source code 
  • Full database contents 
  • Active malware 
  • Weaponized exploit code 
  • Large files 
  • Screenshots containing sensitive data 

MOSAIC Strata may provide an alternate secure communication method after reviewing the initial notice.

8. Information for the Detailed Report

After a secure reporting method has been established, a useful report should include:

  • A clear description of the vulnerability 
  • The affected asset, page, component, or function 
  • Reproduction steps 
  • Preconditions required to reproduce the issue 
  • The observed result 
  • The expected result 
  • Potential security impact 
  • Minimal proof-of-concept information 
  • Relevant request or response details with sensitive values removed 
  • Suggested remediation, when available 
  • Whether the vulnerability has been disclosed to anyone else 
  • Any timeline or coordination concerns 

Reports should contain only the information reasonably necessary to investigate the issue.

9. MOSAIC Strata’s Response

MOSAIC Strata intends to:

  • Review reports submitted in good faith 
  • Acknowledge receipt when sufficient contact information is provided 
  • Evaluate whether the report affects an in-scope system 
  • Request clarification when necessary 
  • Investigate credible findings 
  • Take reasonable steps to reduce confirmed security risk 
  • Communicate material status updates when practical 
  • Coordinate disclosure when appropriate 
  • Treat researchers respectfully when they follow this policy 

Response and remediation time will vary depending on:

  • Severity 
  • Complexity 
  • Reproducibility 
  • Product maturity 
  • Third-party dependencies 
  • Operational risk 
  • Availability of a safe correction 
  • Legal or contractual obligations 

Submission of a report does not guarantee that MOSAIC Strata will classify the issue as a vulnerability or implement a particular correction.

10. Researcher Expectations

Researchers must:

  • Act honestly and in good faith 
  • Follow this policy 
  • Respect privacy and confidentiality 
  • Avoid unnecessary access 
  • Minimize impact 
  • Protect vulnerability information 
  • Avoid public disclosure before coordination 
  • Respond reasonably to requests for clarification 
  • Delete sensitive information when instructed 
  • Avoid misrepresenting their relationship with MOSAIC Strata 

Submitting a report does not create an employment, contractor, agency, partnership, customer, or confidential relationship unless established through a separate written agreement.

11. Coordinated Public Disclosure

Do not publicly disclose a suspected vulnerability before MOSAIC Strata has had a reasonable opportunity to investigate and address it.

Public disclosure includes:

  • Social-media posts 
  • Blog posts 
  • Conference presentations 
  • Videos or livestreams 
  • Public repositories 
  • Vulnerability databases 
  • Mailing lists 
  • Press communications 
  • Distribution of exploit code 
  • Sharing with unrelated third parties 

MOSAIC Strata welcomes reasonable disclosure coordination based on the severity and complexity of the issue.

No fixed disclosure deadline is guaranteed by this policy. A coordinated timeline should consider remediation progress, user risk, third-party dependencies, and the potential impact of disclosure.

12. Safe Harbor

When security research is conducted in good faith and remains fully compliant with this policy, MOSAIC Strata will consider that activity authorized for purposes of the systems MOSAIC Strata owns and controls.

MOSAIC Strata will not initiate legal action against a researcher solely for accidental, good-faith violations of this policy when the researcher:

  • Stops the activity promptly 
  • Avoids further harm 
  • Reports the issue without unreasonable delay 
  • Cooperates with MOSAIC Strata 
  • Does not misuse, retain, disclose, or profit improperly from obtained information 

If MOSAIC Strata believes that research followed this policy and receives a legal inquiry concerning that research, MOSAIC Strata may state that the activity was conducted under this policy.

This safe-harbor statement:

  • Applies only to MOSAIC Strata 
  • Applies only to systems MOSAIC Strata owns and controls 
  • Does not bind third parties 
  • Does not authorize violations of law 
  • Does not authorize testing of third-party infrastructure 
  • Does not waive the rights of customers, service providers, users, or other parties 
  • Does not apply to conduct performed in bad faith or outside this policy 

Researchers remain responsible for obtaining independent legal advice concerning their activities.

13. No Compensation

MOSAIC Strata does not currently operate a paid vulnerability-reward or bug-bounty program.

Submitting a report does not entitle the reporter to:

  • Payment 
  • Reimbursement 
  • Merchandise 
  • Employment 
  • Contract work 
  • Public recognition 
  • Product access 
  • Services 
  • Any other compensation 

Do not conduct testing with an expectation of payment.

Any reward or recognition would require separate written approval from an authorized MOSAIC Strata representative.

14. Duplicate, Informational, and Ineligible Reports

MOSAIC Strata may close reports that are:

  • Duplicates 
  • Previously known 
  • Not reproducible 
  • Out of scope 
  • Theoretical without a meaningful security impact 
  • Reports concerning third-party systems 
  • Spam or automated output without validation 
  • General security recommendations 
  • Missing sufficient detail 
  • Based solely on outdated software-version banners 
  • Missing security headers without demonstrated impact 
  • Self-XSS requiring a victim to execute code against themselves 
  • Clickjacking on pages without sensitive actions 
  • Rate-limiting concerns without demonstrated security impact 
  • Content, spelling, or cosmetic issues 
  • Social-engineering observations 
  • Findings produced through prohibited testing 

This list may change as the website and products evolve.

15. Changes to This Policy

MOSAIC Strata may update this policy as its website, products, infrastructure, reporting capabilities, and security program mature.

The current version will be posted on this page with an updated effective date.

Testing is governed by the policy in effect at the time the activity occurs.

16. Contact

To initiate a responsible disclosure report, use the MOSAIC Strata Contact page.

Begin the message with:

RESPONSIBLE DISCLOSURE REPORT

Do not place sensitive vulnerability information in the initial website submission.

 Copyright © 2026 MOSAIC Strata. All Rights Reserved. 

Powered by

  • Home
  • Company
  • Solutions
  • Insights
  • Contact
  • Privacy
  • Terms
  • Responsible Disclosure
  • Accessibility
  • Trust Center

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept