Trust Center

Responsible disclosure

We welcome reports from security researchers and take them seriously. Here's how to report safely.

Last updated: August 2026

How to report

Send your report to it@mahsumaah.sa with a clear description of the vulnerability, steps to reproduce, potential impact, and any supporting material (screenshots or requests). We will acknowledge receipt, work to verify and remediate, and keep you updated on progress.

What is allowed

  • Test only your own account or test data.
  • If you inadvertently access other people's data, stop and report it immediately.
  • Give us reasonable time to remediate before any public disclosure.

What is not allowed

  • Accessing, modifying, deleting, or downloading other customers' data.
  • Denial-of-service (DoS/DDoS) or intentional overload.
  • Social engineering of our staff or customers, or physical access.
  • Publicly disclosing or exploiting the vulnerability before it is fixed.

Our commitment

We treat good-faith reports that follow these guidelines with respect and will not pursue legal action against researchers who abide by them. We do not currently run a paid bug-bounty program, but we value your contribution and are happy to credit you if you wish.