> Documentation index: https://momentum.atlasapps.us/docs/llms.txt
> Canonical page: https://momentum.atlasapps.us/docs/security

# Vulnerability disclosure policy

Atlas Apps welcomes good-faith security research intended to improve the
security of Momentum. If you make a good-faith effort to comply with this
policy, Atlas Apps will consider your research authorized and will not
initiate legal action against you based on that research.

## Report a security issue

Email security@atlasapps.us. Include the affected app, website, or service,
the steps to reproduce the issue, and its likely impact. Our security contact
details are also published at momentum.atlasapps.us/.well-known/security.txt.

Give Atlas Apps a reasonable opportunity to investigate and remediate an issue
before public disclosure.

## Research rules

Research must avoid accessing, retaining, altering, or disclosing another
person's data; disrupting or degrading Momentum; denial-of-service testing;
social engineering; credential stuffing; physical attacks; spam; persistence
in Atlas Apps systems; or attempts to extort payment.

Test only with accounts and data you own.

If you unexpectedly encounter personal, health, or other sensitive
information, stop testing, do not copy or retain more information than is
necessary to report the issue, and notify us promptly at
security@atlasapps.us.

## Scope and limits

This policy covers the Momentum apps, momentum.atlasapps.us, and the Momentum
account portal. This policy does not authorize testing of third-party systems
and cannot bind third parties or law-enforcement authorities. Report issues in
Apple, Microsoft, OpenAI, or other providers' services to those providers.

## Related information

- [Privacy policy](privacy.md)
- [Consumer health data privacy policy](consumer-health-data.md)
- [Terms of service](terms.md)
