Responsible disclosure

A safe route for reporting public-site security concerns

MGG welcomes responsible, non-disruptive reports related to the public website. Reports must not involve attempts to access private systems, credentials, or data that does not belong to the reporter.

Disclosure guidance

Clear boundaries for safe reporting.

Last reviewed: July 6, 2026.

Security illustration showing public information separated from private operational systems.

How to report

  • Use the contact page and select the security-related subject.
  • Include a short description and steps to reproduce the issue if possible.

Scope

  • Reports should relate to the public website.
  • Do not attempt to access private systems, credentials or data.

Responsible behaviour

  • Please avoid disruptive testing, social engineering, automated attacks or attempts to access information that is not yours.

Reporting route

Use the contact page and select Security report.

Include a concise description of the issue and steps to reproduce it where appropriate.

Contact us

Cookie settings

We use necessary cookies and may use privacy-friendly analytics if enabled and accepted. Privacy policy.

Responsible Disclosure | MGG