Effective: July 26, 2026
MiAngel is dedicated to protecting the security and privacy of the people who trust us with their wellness data. This Vulnerability Disclosure Policy gives security researchers clear guidelines for conducting good-faith vulnerability discovery, and explains how to report the vulnerabilities you find to us. We welcome your research and value your help in keeping MiAngel and its users safe.
We ask that you follow these guidelines when conducting security research:
Notify us as soon as possible after you discover a real or potential security issue.
Give us a reasonable amount of time to resolve the issue before disclosing it publicly.
Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems, and destruction or manipulation of data.
Only use exploits to the extent necessary to confirm a vulnerability. Do not use a vulnerability to compromise data beyond the minimum needed to demonstrate the issue, to establish persistent access, or to pivot to other systems.
If you encounter any sensitive data, including personal information, health information, or financial information, stop immediately, notify us, and do not disclose or retain that data. Keep any such information confidential.
Do not submit a high volume of low-quality reports.
This policy applies to the following systems and services:
The MiAngel website at https://miangel.ai, including the application at https://miangel.ai/dashboard.
MiAngel API endpoints hosted in the miangel-prod Google Cloud Platform project.
The following are out of scope: staging and pre-production environments; third-party services and platforms we rely on, including Google, Stripe, OpenAI, Cloudflare, Resend, and Twilio, which should be reported directly to the respective vendor under their own disclosure programs; and our social media accounts.
If you are not sure whether a system or issue is in scope, email us at security@miangel.ai before you begin.
The following testing methods are not authorized under this policy:
Denial of service (DoS or DDoS) attacks, or any form of load or stress testing.
Physical testing, and social engineering (such as phishing or vishing) of MiAngel staff, users, or contractors.
Testing with accounts or data that do not belong to you. You may only test using accounts you have created yourself, and never with the accounts or data of real users.
To report a vulnerability, please send us a clear description of the issue, the location or endpoint where you found it, its potential impact, and step-by-step instructions to reproduce it. Reports may be submitted anonymously, and you may write to us in English or Spanish. Send your report to security@miangel.ai
When you report a vulnerability in accordance with this policy, we commit to the following:
We will acknowledge receipt of your report within three (3) business days.
We will keep you informed of our progress as we work to resolve the issue.
We will not pursue or recommend legal action against you for security research conducted in good faith under this policy.