Security & Vulnerability Disclosure
Last updated: July 28, 2026
Operator
Reports for Melsun are handled by Vajta Technologies Inc., 1111B S Governors Ave Suite 24501, Dover, DE 19904 US.
Report a vulnerability
We welcome good-faith security research. Email admin@melsun.ai with subject line Security report — melsun.ai. Include steps to reproduce, affected URLs or APIs, and impact assessment if known.
Machine-readable contact details: /.well-known/security.txt.
Safe harbor
If you make a good-faith effort to avoid privacy violations, destruction of data, and disruption of service, and you promptly report findings to us without exploiting them beyond what is needed to demonstrate the issue, we will not pursue legal action related to that research.
Out of scope
- Social engineering of employees or customers
- Denial-of-service / volumetric attacks
- Physical attacks against facilities or devices
- Reports from automated scanners without a demonstrated impact
Response targets
- Critical (active breach, child safety, live fraud): begin triage within 4 hours
- High (confirmed vulnerability): begin triage within 24 hours
- Medium / Low: best effort within 2–5 business days
