Security & Responsible Disclosure
Last updated: July 4, 2026
This page is maintained by the SpendMint team to help security researchers, partners, and providers (including Plaid) reach the right person when reporting a suspected vulnerability or security concern.
Information Security Contact
- Name: Okuich Abella
- Title: Founder & CEO
- Primary email: ok2abella@gmail.com
- Monitored group email: security@spendmint.app
- Business address: 8 The Green, Suite B, Dover, Delaware 19901, USA
This same contact handles Plaid-related security correspondence and is published in our security.txt. Our operationalized controls are documented in the Information Security Policy & Procedures.
Reporting a vulnerability
Email the contact above with a clear description, reproduction steps, affected URLs or endpoints, and any proof-of-concept material. Please do not include real user data.
- We acknowledge reports within 3 business days.
- We aim to provide a status update within 10 business days.
- Please give us reasonable time to remediate before public disclosure.
Safe harbor
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and follow this policy.
Out of scope
- Denial-of-service testing against production.
- Social engineering of SpendMint staff or users.
- Automated scanner output without a demonstrated impact.