Responsible Vulnerability Disclosure Policy

Effective Date: August 2026 · Last Updated: August 2026

Our Commitment to Security

Motenza Capital is committed to protecting the confidentiality, integrity, and security of information entrusted to us by applicants, clients, financial partners, lenders, service providers, and other stakeholders.

We value responsible reports from security researchers and other individuals who identify potential technical vulnerabilities affecting our public-facing digital systems.

This Responsible Vulnerability Disclosure Policy explains how suspected security vulnerabilities should be reported, what limited testing may be conducted, and what activities are not authorized.

This policy is intended to support responsible disclosure. It is not a bug bounty program and does not authorize access to customer information, funding applications, financial records, private systems, or third-party platforms.

Authorized Business Activities

Nothing in this policy limits, restricts, or modifies Motenza Capital’s authorized collection, receipt, review, use, storage, transmission, or disclosure of information in connection with legitimate business activities, including:

  • business financing applications;
  • underwriting and risk evaluation;
  • direct funding using Motenza Capital’s own or affiliated capital;
  • brokerage, referral, placement, or submission to independent lenders and funding partners;
  • review of bank statements and financial records;
  • identity, ownership, and business verification;
  • fraud prevention and suspicious activity review;
  • compliance and legal obligations;
  • customer communication and support;
  • transaction processing;
  • servicing, payments, and collections; and
  • other activities reasonably related to providing or facilitating business financing products and services.

These authorized business activities are governed by Motenza Capital’s Privacy Policy, Terms of Use, application disclosures, electronic consents, customer agreements, partner agreements, and applicable law.

The restrictions in this Vulnerability Disclosure Policy apply only to security testing or research performed by persons who do not have separate written authorization from Motenza Capital.

Systems Within Scope

This policy applies only to publicly accessible, unauthenticated informational webpages that:

  • operate under the motenzacapital.com domain;
  • are owned or directly controlled by Motenza Capital; and
  • are available to the general public without logging in, submitting an application, or uploading documents.

Testing must be limited, non-disruptive, and performed only to the minimum extent necessary to identify and report a suspected vulnerability.

If you are uncertain whether a page, system, or activity is within scope, contact us before proceeding.

Systems and Activities Outside Scope

The following are not authorized for active security testing unless Motenza Capital provides separate written permission:

  • business financing application forms;
  • document-upload features;
  • bank-statement submission or analysis systems;
  • identity-verification systems;
  • authenticated pages or accounts;
  • customer, lender, partner, or administrative portals;
  • application programming interfaces;
  • CRM, email, telephone, messaging, or workflow systems;
  • internal systems, networks, databases, devices, or software;
  • employee, contractor, client, applicant, or partner accounts;
  • payment, banking, servicing, or collection platforms; and
  • any third-party system, integration, application, or infrastructure.

A Motenza Capital logo, link, form, embedded component, or integration does not mean that the underlying system is owned or controlled by Motenza Capital.

Motenza Capital relies on independent hosting, communications, CRM, identity-verification, document-processing, analytics, banking, funding, and technology providers. This policy does not give anyone permission to test systems belonging to those providers.

A suspected vulnerability involving an out-of-scope system may still be reported to Motenza Capital, but you must not attempt to exploit, validate, or investigate it through active testing.

Guidelines for Responsible Research

To remain within this policy, you must:

  • act in good faith and solely for defensive security purposes;
  • test only public informational pages that are within scope;
  • use your own devices, accounts, and information;
  • limit testing to the minimum necessary to identify a suspected issue;
  • avoid accessing information belonging to another person or business;
  • stop immediately if sensitive or confidential information becomes visible;
  • avoid disruption, degradation, data loss, or impairment of any system;
  • report the suspected vulnerability promptly;
  • provide sufficient information for Motenza Capital to understand the issue;
  • keep the vulnerability confidential while it is being reviewed; and
  • comply with applicable law.

Do not continue testing after you have obtained sufficient information to describe the suspected issue.

Prohibited Activities

The following activities are expressly prohibited:

  • denial-of-service or distributed denial-of-service testing;
  • traffic flooding, load testing, or resource exhaustion;
  • phishing, social engineering, impersonation, or pretexting;
  • physical security testing;
  • credential stuffing, password spraying, or brute-force attacks;
  • attempting to access another person’s account;
  • use of stolen, leaked, purchased, or third-party credentials;
  • introducing malware, ransomware, spyware, destructive code, or malicious files;
  • installing backdoors or establishing persistent access;
  • privilege escalation beyond what is strictly necessary to describe a suspected issue;
  • lateral movement into another system, account, network, or application;
  • altering, deleting, encrypting, corrupting, or making data unavailable;
  • downloading, copying, retaining, or transmitting confidential information;
  • accessing real funding applications, bank statements, identification records, tax documents, ownership records, or customer communications;
  • high-volume automated scanning;
  • automated submission of applications, forms, messages, or files;
  • testing employees, contractors, applicants, clients, lenders, funding partners, or service providers;
  • threatening disclosure, business interruption, or reputational harm;
  • requesting payment in exchange for withholding information; and
  • any activity that violates applicable law or the rights of another party.

Sensitive Information

Motenza Capital may process sensitive business, financial, ownership, application, and identification information.

You are not authorized to intentionally access, inspect, collect, copy, download, retain, transmit, modify, or disclose:

  • bank statements;
  • financial statements;
  • tax documents;
  • business formation records;
  • identification documents;
  • Social Security numbers;
  • tax identification numbers;
  • ownership information;
  • funding applications;
  • account credentials;
  • authentication information;
  • customer communications;
  • confidential business records; or
  • personal information belonging to another individual.

If sensitive information is encountered unintentionally:

  • stop testing immediately;
  • do not continue viewing or exploring the information;
  • do not copy, download, photograph, transmit, or share it;
  • notify Motenza Capital promptly; and
  • securely delete any inadvertently retained information after coordinating with us.

Any screenshots or supporting evidence must be carefully redacted.

How to Report a Vulnerability

Send suspected technical security vulnerabilities to:

security@motenzacapital.com

Use the subject line:
Security Report — Brief Description

Please include, where available:

  • the affected webpage or domain;
  • a clear description of the suspected vulnerability;
  • the potential security impact;
  • limited and reproducible steps demonstrating the issue;
  • the date and approximate time the issue was observed;
  • relevant browser, device, or software information;
  • a minimal proof of concept;
  • redacted screenshots or supporting details; and
  • your preferred contact information.

Do not send passwords, active credentials, executable malware, complete bank statements, identification documents, or unredacted customer information by email.

This email address is only for technical security reports.

General customer service, application, account, funding, privacy, fraud, and legal inquiries should be sent through the appropriate Motenza Capital contact channel.

What You Can Expect From Motenza Capital

Motenza Capital will make reasonable efforts to:

  • acknowledge legitimate reports;
  • conduct an initial review;
  • request additional information when necessary;
  • evaluate the potential severity and impact;
  • coordinate with affected service providers when appropriate;
  • prioritize confirmed vulnerabilities based on risk; and
  • communicate with the reporter when reasonably practicable.

Resolution times may vary depending on the nature of the issue, technical complexity, third-party involvement, legal obligations, and the availability of an appropriate corrective action.

Acknowledgment of a submission does not mean that Motenza Capital has confirmed the existence of a vulnerability.

Motenza Capital may close reports that are incomplete, duplicative, unverifiable, out of scope, purely theoretical, generated only by an automated scanner, or inconsistent with this policy.

Safe Harbor for Good-Faith Research

When research is performed in good faith, remains within the scope of this policy, complies with all restrictions, avoids harm, and is promptly reported to Motenza Capital, we will treat that activity as authorized under this policy and do not intend to pursue legal action solely because of that compliant research.

If an accidental violation occurs, stop immediately, notify us, explain what happened, and cooperate with reasonable steps necessary to protect affected systems and information.

This safe harbor:

  • applies only to systems Motenza Capital is legally authorized to include;
  • does not authorize testing of third-party systems;
  • does not bind lenders, banks, vendors, service providers, government agencies, or other third parties;
  • does not protect malicious, unlawful, reckless, deceptive, destructive, or extortionate conduct;
  • does not waive Motenza Capital’s rights concerning conduct outside this policy; and
  • does not authorize violations of applicable law.

When uncertain, request written clarification before taking further action.

Coordinated Disclosure

Do not publicly disclose a suspected or confirmed vulnerability, technical evidence, screenshots, affected information, or communications with Motenza Capital without prior written coordination.

We ask reporters to provide Motenza Capital with a reasonable opportunity to investigate, coordinate with affected providers, and address confirmed issues before any public disclosure is considered.

Submission of a report does not create a right to publish confidential, personal, financial, proprietary, or security-sensitive information.

No Bug Bounty or Compensation Commitment

This is a vulnerability disclosure process, not a bug bounty program.

Motenza Capital does not promise or guarantee:

  • monetary compensation;
  • reimbursement;
  • gifts;
  • employment;
  • commercial engagement;
  • public recognition; or
  • any other reward.

No payment or benefit is owed unless Motenza Capital expressly agrees to it in writing in advance.

A reporter must not condition confidentiality, deletion of information, non-disruption, or responsible disclosure on receiving compensation.

Policy Updates

Motenza Capital may update this policy as its operations, technology environment, security practices, service-provider relationships, and legal obligations evolve.

The current version will be the version published on the official Motenza Capital website.

Security Contact

Motenza Capital
Security Reports: security@motenzacapital.com
General Support: support@motenzacapital.com