Please do not disclose a suspected vulnerability publicly before Mukta has had a reasonable opportunity to investigate and address it.
Send reports to licensing@mukta.app with subject Mukta Zero security report and include, where reasonably possible:
- affected version or commit;
- a concise description of the issue and potential impact;
- the environment in which it was observed;
- reproducible steps that do not expose third-party systems or data; and
- any mitigation you have identified.
Do not include credentials, personal data, confidential third-party information, or data obtained from systems you were not authorized to test.
Mukta welcomes good-faith research involving Mukta Zero or systems you own or are expressly authorized to test, consistent with applicable law and ACCEPTABLE-USE-POLICY.md.
Authorization to test Mukta Zero does not authorize testing of Mukta’s unrelated infrastructure, third-party services, other users, or any system you do not own or have permission to test.
Mukta Zero can generate and execute code. Use appropriate isolation, least-privilege credentials, backups, access controls, and human review before running generated code against important environments or data.