Security and Responsible Disclosure
Last updated: September 17, 2026
Mythos Software, LLC operates Mythos. Security reports: support@mythos.new. The machine-readable contact is security.txt.
Protecting the service
Mythos uses authenticated account access, workspace/project permissions and restricted server operations. Stored connector credentials are encrypted, and sign-in tokens and secret credentials are excluded from portable account exports. Generated-code execution has a separate runtime boundary; published content is served as the selected build artifact.
Error telemetry is configured to reduce sensitive data: common secret and content fields are scrubbed, and application session replay is disabled. These controls reduce risk; they do not guarantee that every software error or disclosure can be prevented.
The Privacy Policy, Subprocessors register and Data Processing Agreement describe data roles and relevant provider boundaries. We do not claim a Mythos SOC 2 or ISO 27001 certification on the basis of a provider’s certification.
Account and workspace controls
Personal two-factor authentication is available on every plan. An enrolled account uses an authenticator code to complete sign-in before accessing private product areas. Add and verify a backup authenticator before replacing a device. Mythos does not currently issue recovery codes; administrative access requires a verified authenticator.
Business workspace owners and administrators can manage default project access, workspace invitations, invite links, publishing authority and Share Preview access in Settings → Privacy & security. Changes are checked when the protected action is admitted. A saved restriction remains effective after a plan downgrade. An already admitted publish can finish, and a preview artifact link already issued can remain usable for up to five minutes.
These controls have separate scopes: restricting preview sharing does not unpublish a website, and restricting new workspace email invitations does not invalidate invitations already sent. See Privacy and security settings for the available controls and their limits.
Report a vulnerability
Include the affected URL or component, a description of the issue, minimal steps to reproduce it and the potential impact. Use synthetic data and your own account where possible. Do not include another person’s private content or live credentials. We may arrange an appropriate channel for sensitive evidence.
We aim to acknowledge reports within 72 hours. Investigation and remediation depend on the severity and facts; we will communicate about a validated issue and coordinated disclosure. An acknowledgement target is not a guarantee of a completed fix within that period.
Authorized good-faith research
Use the least intrusive method needed to demonstrate the issue. Stop if you encounter another person’s data and report the access without copying, changing or deleting it. Do not disrupt availability, perform social engineering, send phishing messages, attempt credential theft, or access third-party systems without their authorization.
Mythos will not pursue legal action for good-faith research that follows this policy and applicable law. This statement covers Mythos’s own rights only; it does not authorize activity against another party or waive that party’s rights.
Please coordinate disclosure with us so affected users can be protected. This policy does not create a paid bounty program or promise a reward.
Account and privacy issues
For an account problem use support@mythos.new. For access, correction or deletion of personal data use privacy@mythos.new. An active security incident should be reported to support@mythos.new with the subject “Security report”.