← Back to MentoCore

Security & Vulnerability Disclosure

Security contact: security@hospitalitymentors.net. This page describes the controls we operate today, how to report a vulnerability, and what we commit to in response.

Reporting a vulnerability

Email security@hospitalitymentors.net with enough detail to reproduce the issue: affected URL, steps, payload, and impact. Our machine-readable contact is published at /.well-known/security.txt.

Our response commitments

  • Acknowledgement within 2 business days.
  • Triage and severity assessment within 5 business days.
  • Fix or documented mitigation: critical 7 days, high 30 days, medium 90 days.
  • Credit in our advisory if you would like it, and confirmation when the fix ships.

Safe harbour and rules

We will not pursue legal action for good-faith research that follows this policy. Please do not access, modify, or exfiltrate other customers' data, degrade the service, run automated load or denial-of-service tests, or use social engineering or physical attacks. Test only against accounts you control, and give us a reasonable window to remediate before public disclosure (we suggest 90 days). We do not currently run a paid bug bounty.

Controls in place today

  • TLS in transit; encryption at rest on managed storage.
  • Row-level security on every application table, enforcing per-organization tenant isolation.
  • Roles stored in a dedicated table and validated server-side on every privileged call.
  • Optional TOTP two-factor authentication, plus leaked-password protection and a minimum password length.
  • Audit events for record changes and privileged actions, exportable by organization admins.
  • Public webhook and scheduled endpoints require a bearer secret.
  • Continuous dependency vulnerability scanning and database security linting.

Availability, backup and recovery

We target 99.5% monthly availability. Managed Postgres backups support point-in-time recovery with a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 4 hours for a full-region restore. Incidents affecting availability or data are communicated to workspace owners by email; a hosted status page is on our roadmap.

Breach notification

If a personal data breach affects customer data we notify the affected workspace owners without undue delay and within 72 hours of becoming aware, as committed in the DPA.

Compliance roadmap

MentoCore does not currently hold SOC 2 or ISO 27001 certification and we do not claim otherwise. Our stated roadmap:

  • Now — GDPR/UK GDPR processor terms, DPA, sub-processor register, self-service export and deletion, 2FA, audit-log export.
  • Next — formal policy set (access control, incident response, change management), penetration test, hosted status page.
  • Then — SOC 2 Type I readiness assessment, followed by Type II observation.

Security questionnaires and our current control summary: security@hospitalitymentors.net.

Last updated 2 September 2026. Hospitality Mentors Inc · Hospitality Mentors Inc, New York, NY, United States