M3LYSecurity

Security & responsible reporting

Report the problem, not the secret.

Security, privacy and abuse reports for the M3LY private beta can be sent to hello@m3ly.me.

What to include

Enough detail to reproduce safely.

Include the affected M3LY surface, version/build if known, steps to reproduce, observed impact and the minimum evidence necessary. Redact unrelated personal data. Do not email credentials, private keys, recovery secrets, passkey private material or live device secrets.

Research boundaries

Avoid harm.

Do not use destructive testing, denial of service, social engineering, credential attacks, persistence, mass data access, privacy-invasive collection or testing against accounts you do not control. Stop if you encounter private user content or evidence that continued testing could cause harm.

Current capability truth

No security claim ahead of qualification.

Production private messaging remains disabled until the E2EE qualification gate is satisfied, with no plaintext fallback. Voice and alternative/offline transports remain disabled or unqualified unless separately released. A report should distinguish active production behaviour from disabled research/scaffold code.

Abuse & privacy

Use the same contact during beta.

Reports of spam, phishing, impersonation, privacy abuse or machine-account deception can be sent to hello@m3ly.me. Do not send unnecessary copies of harmful or sensitive material; describe it and provide the minimum evidence needed for review.