Legal & Privacy

Security & Vulnerability Disclosure

Effective: August 16, 2026

Manifest Labs takes the security of our users, creators, and their creations seriously. We welcome good-faith security research and responsible disclosure.

1. How to report

Email support@manifestanything.ai with the subject “Security Vulnerability Report”. Please do not open a public issue or post details publicly before we have had a reasonable window to investigate and fix the issue.

2. What to include

  • The affected URL, product, or component (website, API, demo, console-related service).
  • A clear description of the vulnerability and its potential impact.
  • Step-by-step reproduction instructions.
  • Supporting screenshots or logs, where appropriate.
  • Your contact information and, if you wish, how you would like to be credited.

3. Testing boundaries

When researching, please:

  • Do not access, modify, or exfiltrate other users’ data beyond what is strictly necessary to demonstrate the issue.
  • Do not perform destructive testing, delete data, or disrupt services.
  • Do not use social engineering, phishing, or physical attacks against users, staff, or infrastructure.
  • Do not run automated scanners at high volume against production.
  • Avoid privacy violations; if you encounter personal data, stop and tell us what you saw without retaining it.

We will not pursue legal action against researchers who act in good faith and follow these boundaries. Manifest Labs does not currently operate a paid bug-bounty program; we acknowledge and thank researchers for valid reports.

4. What to expect from us

  • Confirmation of receipt within a reasonable time.
  • A good-faith investigation and, where warranted, a fix and deployment.
  • Updates on the status of your report as the work proceeds.
  • Credit in release notes if you would like it, unless you prefer anonymity.