TapMind
OpenMediationMarketplaceGrowth DSPCreative Studio
OpenMediationGrowth DSP
Sign upSign up
OpenMediationMarketplaceGrowth DSPCreative Studio
Company
About UsMaking a Difference (CSR)Industry Events and NewsContact Us
CareersBlogPublisher Referral ProgramDeveloper Docs
Login
PlatformsOpenMediationGrowth DSP
Sign upSign up
Company
About UsMaking a Difference (CSR)Industry Events and NewsContact Us
CareersBlogPublisher Referral ProgramDeveloper Docs
  1. Home
  2. Legal
  3. Security
  4. Report a Vulnerability

Report a Vulnerability

TapMind trust and compliance information for security researchers.

Email the security team

Your email application will open with a structured report template. Nothing is submitted through this website.

Start a security reportStart a security report

Report a security vulnerability

We appreciate the work of security researchers. If you believe you have found a vulnerability in a TapMind system, please tell us, and we will work with you to understand and resolve it quickly.

How to report. Email security@tapmind.com with: a description of the issue and where it is; steps to reproduce (a proof of concept is welcome; please do not include real personal data); the impact you believe it has; and how we can reach you. Our machine-readable contact details are at security.txt.

What is in scope. tapmind.com and its subdomains; the TapMind platform (mediation.tapmind.io); TapMind's serving and telemetry endpoints; the TapMind SDKs. Out of scope: third-party services and partners' systems (report to them directly); denial-of-service or volumetric testing; social engineering, phishing or physical attacks; automated scanning that degrades service; issues that require a compromised device or account; reports of missing best-practice headers without a demonstrated impact; findings in apps that merely include our SDK (report to the app's publisher).

What we ask of you. Act in good faith: access only the minimum data needed to demonstrate the issue, do not access, modify or retain personal data belonging to others, do not disrupt service, and give us reasonable time to remediate before any public disclosure. We ask for at least 90 days from acknowledgement, or longer for complex fixes by agreement.

What you can expect from us. We will acknowledge your report within 5 business days, keep you informed of our progress, and tell you when the issue is resolved. We will not pursue legal action against researchers who follow this policy in good faith, and we will not refer such research to law enforcement. If you comply with this policy, we consider your research authorised for the purposes of applicable anti-hacking and anti-circumvention laws to the extent we are able to authorise it. We do not currently operate a bug-bounty programme and do not offer rewards, but with your permission we will credit you when a fix is published.

Personal data. If you encounter personal data during your research, stop, do not retain it, and tell us in your report. We process the contact details you give us only to handle your report, under our Privacy Policy.

Thank you for helping keep TapMind's publishers and their users safe.

TapMind

An Intelligent AdTech Ecosystem that Drives Publisher Growth through OpenMediation, Additional Demand, and Intelligent Yield Optimization.

Rated 4.3 out of 5 on G2Rated 4.5 out of 5 on Trustpilot
GamingNon-GamingAgencies & Advertisers
OpenMediationMarketplaceGrowth DSPCreative Studio
Developer DocsGlossaryPrivacy & consent with the TapMind SDKSDK Licence
AboutCareersPublisher Referral ProgramContact
LegalYour Privacy ChoicesSecurityReport a Vulnerability
Stay in the loop

Practical insights on publisher monetization, demand and AdTech, without the noise.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

© 2026 TapMind Technologies Pvt Ltd

Privacy PolicyTerms of UseCookie PreferencesDo Not Sell or Share My Personal InformationSitemap
Back to top