Report a vulnerability

If you found something, we want it before anyone else does. A monitored address, an answer within five business days, and safe harbour for reporting in good faith.

How to reach us

Email security@mercleo.com. The address is monitored directly by the people who build the product.

A machine-readable pointer lives at /.well-known/security.txt. We do not publish an encryption key yet; if your report is sensitive enough to need one, say so in a first email that omits the details and we will arrange a secure channel.

What happens next

We acknowledge reports within five business days, and in practice usually sooner. We will tell you what we found, keep you posted while we work on it, and let you know when a fix ships.

How fast a fix ships depends on severity. We prioritize reports that expose customer data over everything else in flight.

Safe harbour

We will not pursue or support legal action against anyone who researches and reports a vulnerability in good faith, stays within the scope below, avoids privacy violations and service degradation, and gives us reasonable time to fix the issue before disclosing it publicly.

If you are ever unsure whether something is in scope, ask first. We answer that email quickly.

Scope

In scope: mercleo.com and the Mercleo-operated applications on mercleo.com subdomains.

Out of scope:

  • Denial-of-service or volumetric testing of any kind.
  • Social engineering or phishing of Mercleo staff or customers.
  • Physical attacks against people, offices, or infrastructure.
  • Third-party services we use (Stripe, Supabase, Vercel, and the rest of our subprocessor list); report those to the provider.
  • Automated scanner output without a demonstrated issue behind it.
  • Spam, SPF/DKIM/DMARC configuration reports, and clickjacking on pages with no sensitive action.

If you reach another customer's data

Stop at the minimum needed to demonstrate the issue, do not retain or share what you saw, and tell us immediately. Tenant isolation is the property we care most about; a report that proves a gap in it will get our fastest response.

Recognition

With your permission, we credit reporters when a fix ships. We do not run a paid bounty program today; if that changes, this page will say so.

The rest of the trust centre. Everything else a reviewer asks for.

Found something urgent? Skip the reading. Email security@mercleo.com now.