Security Disclosure Policy
Last updated: April 5, 2026
At M&R Edge Studio (operated by Michelle & Rich Essence Ltd), we take the security of our platform and users seriously. We welcome responsible security research and appreciate the efforts of security researchers who help us keep our platform safe.
1. How to Report a Vulnerability
If you believe you have discovered a security vulnerability in our platform, please report it responsibly by emailing us at:
security@mredgestudios.comPlease do not report security vulnerabilities through public GitHub issues, social media, or any other public channel.
2. What to Include in Your Report
To help us investigate and resolve the issue quickly, please include:
- Description — A clear explanation of the vulnerability and its potential impact
- Steps to reproduce — Detailed, step-by-step instructions to reproduce the issue
- Affected component — The URL, API endpoint, or feature where the vulnerability exists
- Impact assessment — Your evaluation of the severity (e.g., data exposure, privilege escalation)
- Proof of concept — Screenshots, logs, or code snippets demonstrating the issue (if applicable)
- Your contact information — So we can follow up with questions or updates
3. Our Response Commitment
When you submit a report, here's what you can expect:
Acknowledgement within 48 hours — We will confirm receipt of your report and assign a tracking reference
Initial assessment within 5 business days — We will evaluate the severity and provide an estimated timeline for a fix
Resolution within 30 days — For confirmed vulnerabilities, we aim to deploy a fix within 30 days (critical issues may be addressed sooner)
Credit and recognition — With your permission, we will acknowledge your contribution in our security hall of fame
4. Safe Harbor
We support responsible disclosure and will not pursue legal action against researchers who:
- Act in good faith and comply with this policy
- Avoid accessing, modifying, or deleting data belonging to other users
- Do not degrade, disrupt, or compromise the availability of our services
- Report vulnerabilities promptly and do not publicly disclose them before a fix is deployed
- Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
We consider security research conducted in accordance with this policy to be authorised conduct under applicable laws, including the Computer Misuse Act 1990 (UK) and Nigeria's Cybercrimes Act 2015.
5. Scope
The following assets are in scope for security research:
- Web application — michelleandrichedgestudio.com and all subdomains
- API / Backend functions — All publicly accessible edge functions and API endpoints
- Authentication flows — Login, signup, password reset, and OAuth integrations
- Social publishing integrations — TikTok, Meta/Instagram, and other connected platform flows
The following are out of scope:
- Denial-of-service (DoS/DDoS) attacks
- Social engineering or phishing of M&R Edge Studio staff or users
- Physical security of offices or data centres
- Third-party services not operated by M&R Edge Studio (e.g., Stripe, Cloudflare)
- Vulnerabilities in outdated browsers or plugins
This policy is governed by the laws of Scotland. For general enquiries, contact us at info@mredgestudios.com.
Michelle & Rich Essence Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZC202456 (security number CSN9839688).
© 2026 Michelle & Rich Essence Ltd. All rights reserved.