Mingloft

Security

Last updated: January 2026

Our commitment to security

Security is a core part of how we build Mingloft. We take the protection of our customers' data seriously and work continuously to maintain and improve our security posture. This page describes our security programme and how to report vulnerabilities responsibly.

Security measures

Mingloft implements the following security controls:

  • Encryption in transit: All data transmitted between your browser and Mingloft is encrypted using TLS 1.2 or higher (HTTPS).
  • Encryption at rest: All data stored in our databases is encrypted at rest using AES-256.
  • Password security: Passwords are hashed using bcrypt. We never store passwords in plain text.
  • Access controls: Role-based access controls limit what each user can see and do.
  • Multi-factor authentication: MFA is available for all planner accounts and strongly encouraged for team workspaces.
  • Audit logging: Security-relevant actions are logged with 90-day retention.
  • Rate limiting: Authentication and public endpoints are rate-limited to prevent abuse.
  • Infrastructure security: Hosted on Heroku and Vercel, both maintaining SOC 2 Type II certification.
  • Backups: Automated daily backups with 90-day retention.
  • Monitoring: Continuous uptime and anomaly monitoring.

Vulnerability disclosure programme

We operate a responsible disclosure programme. If you have discovered a potential security vulnerability in Mingloft, we would like to hear from you. We ask that you:

  • Report the vulnerability to us before disclosing it publicly.
  • Give us a reasonable amount of time to investigate and address the issue before any public disclosure.
  • Make a good-faith effort to avoid privacy violations, destruction of data, or interruption of service during your research.
  • Do not access, modify, or delete data belonging to other users.

What we commit to you

  • We will acknowledge receipt of your report within 48 hours.
  • We will provide an initial assessment of severity and expected timeline within 5 business days.
  • We will keep you informed of our progress.
  • We will not pursue legal action against researchers who act in good faith and follow these guidelines.
  • Critical vulnerabilities will be addressed within 7 days; high severity within 30 days.

In scope

  • www.mingloft.com and all subdomains
  • Mingloft API (mingloft-production-3ade66b2a4f6.herokuapp.com)
  • Mingloft iOS and Android applications

Out of scope

  • Social engineering attacks against Mingloft staff or users
  • Physical security
  • Denial of service attacks
  • Vulnerabilities in third-party services we use (report those to the respective vendor)
  • Issues that require physical access to a user's device

How to report

Send your vulnerability report to security@mingloft.com. Please include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce the issue.
  • Any proof-of-concept code or screenshots (if applicable).
  • Your suggested fix (if you have one).

You may encrypt your report using our PGP key (available on request).

Security contact

security@mingloft.com

For urgent security issues only. For general support, use support@mingloft.com.

Bug bounty

We do not currently operate a paid bug bounty programme. We offer public recognition (with your permission) for significant vulnerability disclosures.