Found something? Please tell us.
Memlane holds people’s photographs, locations, health and relationships. If you have found a way to reach data you should not be able to reach, we would much rather hear it from you than read about it later. Write to security@memlane.ai.
How to report
Email security@memlane.ai with enough detail to reproduce the issue: the endpoint or screen, the steps, and what you were able to see or do that you should not have been. A short proof of concept helps more than a scanner report.
Machine-readable contact details are at /.well-known/security.txt.
What we promise
- We will acknowledge your report within 3 business days and tell you what we intend to do about it.
- We will not pursue you — legally or otherwise — for research conducted in good faith under the rules below.
- We will credit you when a fix ships, if you want to be credited.
- We will keep you informed rather than going quiet. Please give us 90 days before disclosing publicly, and tell us if you plan to disclose sooner so we can work to your timeline instead of arguing about it.
What we ask
- Use your own account and your own data. If a bug lets you reach someone else’s record, stop at the point you have demonstrated it — do not read, download or keep their data. Tell us what you could have reached; you do not need to prove it by taking it.
- No denial of service, no spam, no social engineering of our users or anyone we work with, and no physical attacks.
- Do not run automated scanners at volume. They find little here and they degrade the service for real people.
- Do not modify or delete data that is not yours.
In scope
memlane.ai, api.memlane.ai, the Memlane iOS
app, and the Memlane API — in particular anything that crosses a user
boundary. Memlane is built so that one person’s record cannot be reached
from another account; a working path across that line is the most valuable
thing you can find here, and we will treat it that way.
Out of scope: findings in third-party services we use rather than in Memlane itself (report those to the provider), missing security headers with no demonstrated impact, best-practice reports from automated tools without a working exploit, and social-engineering scenarios.
Rewards
Memlane is a small independent product and does not run a paid bounty programme today. What we can offer is a fast, human response, public credit if you want it, and a fix. If you find something serious, tell us anyway — we would rather owe you thanks than have the bug.