Security

MENTRA LABS, INC.

Last Updated: August 26, 2026

We welcome good-faith reports from security researchers and users who believe they have found a vulnerability affecting a Mentra-owned product or service. This page explains how to report an issue and what you can expect from us.

Report a Vulnerability

Email reports to security@mentraglass.com. Please do not send vulnerability details through customer support, social media, or public issue trackers.

Please include as much of the following as possible:

  • The affected product, service, repository, URL, or version
  • A description of the vulnerability and its potential impact
  • Clear steps to reproduce the issue
  • Relevant logs, screenshots, or proof-of-concept code
  • Whether you believe user data or accounts may be affected
  • Your preferred contact information and disclosure timeline

Scope

This policy applies to security vulnerabilities in Mentra-owned products and services, including:

  • Mentra Live hardware and firmware
  • MentraOS and official Mentra SDKs
  • The Mentra App and first-party Mentra miniapps
  • Mentra-operated cloud services and APIs
  • Mentra-owned websites and developer services

Third-party miniapps, services, and infrastructure not operated by Mentra are outside our direct scope. Please report those issues to the responsible provider. You may copy us if the issue also affects the Mentra platform or Mentra users.

Research Guidelines

When conducting security research, please:

  • Act in good faith and comply with applicable law
  • Test only accounts and devices you own or are expressly authorized to use
  • Make a reasonable effort to avoid privacy violations, data loss, service disruption, and degradation of our services
  • Stop testing and notify us promptly if you encounter personal information, credentials, or other sensitive data
  • Access, retain, and disclose only the minimum data necessary to demonstrate the vulnerability
  • Do not use social engineering, phishing, physical threats, denial-of-service attacks, spam, or destructive techniques
  • Give us reasonable time to investigate and remediate the issue before public disclosure

Safe Harbor

If you make a good-faith effort to follow this policy, we will consider your research authorized and will not initiate legal action against you for that research. If a third party initiates legal action based on research that complied with this policy, we will take reasonable steps to make it known that your activity was conducted under this policy. This safe harbor does not authorize activity against third-party systems or activity prohibited by applicable law.

What to Expect

  • We aim to acknowledge reports within five business days
  • We aim to provide an initial assessment or request additional information within ten business days
  • We will share status updates when practical and coordinate on remediation and public disclosure
  • We will handle your contact information in accordance with our Privacy Notice

Response and remediation time depends on the complexity and severity of the report. These timelines are targets, not guarantees. This disclosure program does not promise monetary rewards.

Other Requests

For account or product help, visit Mentra Support. For privacy rights or questions, email privacy@mentraglass.com.

Ready to build on Mentra?

Open-source moves fast. Stay up to date with the platform.

No spam. Unsubscribe anytime.