Report a vulnerability
If you found something, we want it before anyone else does. A monitored address, an answer within five business days, and safe harbour for reporting in good faith.
How to reach us
Email security@mercleo.com. The address is monitored directly by the people who build the product.
A machine-readable pointer lives at /.well-known/security.txt. We do not publish an encryption key yet; if your report is sensitive enough to need one, say so in a first email that omits the details and we will arrange a secure channel.
What happens next
We acknowledge reports within five business days, and in practice usually sooner. We will tell you what we found, keep you posted while we work on it, and let you know when a fix ships.
How fast a fix ships depends on severity. We prioritize reports that expose customer data over everything else in flight.
Safe harbour
We will not pursue or support legal action against anyone who researches and reports a vulnerability in good faith, stays within the scope below, avoids privacy violations and service degradation, and gives us reasonable time to fix the issue before disclosing it publicly.
If you are ever unsure whether something is in scope, ask first. We answer that email quickly.
Scope
In scope: mercleo.com and the Mercleo-operated applications on mercleo.com subdomains.
Out of scope:
- Denial-of-service or volumetric testing of any kind.
- Social engineering or phishing of Mercleo staff or customers.
- Physical attacks against people, offices, or infrastructure.
- Third-party services we use (Stripe, Supabase, Vercel, and the rest of our subprocessor list); report those to the provider.
- Automated scanner output without a demonstrated issue behind it.
- Spam, SPF/DKIM/DMARC configuration reports, and clickjacking on pages with no sensitive action.
If you reach another customer's data
Stop at the minimum needed to demonstrate the issue, do not retain or share what you saw, and tell us immediately. Tenant isolation is the property we care most about; a report that proves a gap in it will get our fastest response.
Recognition
With your permission, we credit reporters when a fix ships. We do not run a paid bounty program today; if that changes, this page will say so.
The rest of the trust centre. Everything else a reviewer asks for.
- Where your data livesWhere the infrastructure runs, who runs it, and whose law can reach the data.
- SubprocessorsEvery third party that touches customer data, and what each one sees.
- SecurityTenant isolation, staff access, and the supply chain.
- Privacy and your rightsThe processing agreement, retention, export, deletion and breach notice.
- AI and your dataWhat uses a model, what gets sent, and whether it trains on anything.
- AccessibilityWhat has actually been checked, what has not been assessed, and how to report a barrier.
- ComplianceWhat we hold, what we are working towards, and what we do not have.