Found a vulnerability? We want to hear from you.
Security researchers make the whole ecosystem safer. If you've found a potential vulnerability in merlon, we'd genuinely like to know — and we'll work with you in good faith to understand and fix it. This page sets out our scope, the rules, our safe-harbor commitment, and how to reach the team.
B54F 2A19 7D6E 8C1B 3F02 A9D4
Coordinated disclosure makes everyone safer
"We'd rather hear about a flaw from a researcher than from an attacker. A report is a gift — and we treat it like one."
merlon runs two in-house security teams and gates every release, but no program catches everything. External researchers see our systems with fresh eyes and different tools, and that perspective is genuinely valuable to us. This policy exists to make it easy and safe to tell us what you've found — with clear scope, a good-faith safe harbor, and committed response times — so a potential problem becomes a fixed one before anyone is harmed.
What's in scope — and what isn't
Please focus your testing on the systems below. Anything outside this list is out of scope and may cause harm to us or third parties.
In scope
- merlon.ch and its authenticated web application
- The public API (api.merlon.ch, regional endpoints)
- Authentication, session, and access-control logic
- Data isolation between tenants and vaults
- Injection, SSRF, RCE, and similar high-impact classes
Out of scope
- Denial-of-service or volumetric load testing
- Social engineering of staff, customers, or vendors
- Physical attacks against offices or data centres
- Third-party services and sub-processors we don't control
- Reports from automated scanners with no demonstrated impact
Test in good faith, and we've got your back
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorised, will not pursue or support legal action against you, and will work with you to understand and resolve the issue quickly.
Respect privacy
Only interact with accounts you own or have explicit permission to test. Never access, modify, or exfiltrate other customers' data.
Minimise impact
Stop as soon as you've demonstrated a vulnerability. Don't degrade the service, and don't run destructive or high-volume tests.
Give us time
Report promptly and privately, and allow a reasonable period to remediate before any public disclosure.
Stay lawful
Don't violate any law, and don't use findings for extortion. Safe harbor covers good-faith research within this policy.
Getting your report to us
Send us enough detail to reproduce the issue. Encrypted reports are welcome using our PGP key.
Email the team
Write to security@merlon.ch with a clear title, affected component, and impact.
Encrypt if sensitive
For sensitive details, encrypt with our PGP key (fingerprint below). The key is published at the Encryption: URL in our security.txt.
Include repro steps
Provide steps to reproduce, a proof-of-concept, and any logs or screenshots that help us confirm quickly.
- security@merlon.ch
- PGP fingerprint
9F2C 4A7B E1D8 6C03 B54F 2A19 7D6E 8C1B 3F02 A9D4- security.txt
- /.well-known/security.txt (RFC 9116)
- Preferred language
- English
What you can expect from us
Target timelines from the moment we receive a valid report. We'll keep you updated at each stage.
| Stage | Target time | What happens |
|---|---|---|
| Acknowledgement | Within 2 business days | We confirm receipt and assign a handler. |
| Triage & validation | Within 5 business days | We reproduce, assess severity, and confirm scope. |
| Resolution target | Risk-based | Critical issues prioritised; timeline shared with you. |
| Closure & thanks | On fix / mitigation | We confirm the fix and, with consent, add you to our thanks. |
How we work together on a fix
Good disclosure is a two-way street. Here's what we commit to, and what we ask of you, once a report is in.
What we'll do
- Acknowledge your report within two business days
- Keep you updated as we triage and remediate
- Not pursue legal action for good-faith research
- Credit you publicly, with your consent
What we ask of you
- Give us reasonable time to fix before disclosing
- Avoid accessing or altering others' data
- Keep report details confidential until resolved
- Never use a finding for extortion or gain
How we prioritise
We assess severity by real-world impact and exploitability, not by report volume. A rough guide:
- Critical
- Remote code execution, cross-tenant data access, authentication bypass, or mass data exposure. Prioritised immediately.
- High
- Privilege escalation, significant access-control flaws, or injection with meaningful impact.
- Medium
- Issues requiring specific preconditions or limited impact — e.g. stored XSS in a constrained context.
- Low / informational
- Best-practice deviations with minimal exploitability. We still appreciate the heads-up.
Hall of thanks
We don't run a paid bug bounty — our program is recognition-based. With your consent, we're glad to credit researchers who help us improve. Contributions to date are listed anonymously below.
Disclosure questions
Encryption: URL in our security.txt. The fingerprint is listed in the How to report section.