Where to report
Email the security contact.
Tell us about a suspected vulnerability in a Maharlika IX service. Give enough detail to investigate, without exposing private data or disrupting services.
Email the security contact.
The affected address or service, the time you saw the problem, safe steps to reproduce it, what you expected and what happened, and the likely impact. Tell us how to reach you.
Do not access data that belongs to other people, send credentials in a report, disrupt production traffic, or publish details before we have coordinated. Remove secrets from screenshots and logs.
For reachability or operational problems, contact the NOC instead. Maharlika IX does not run a bug bounty, and this page does not authorise intrusive testing.