merlon
Log In
Pricing
Responsible Disclosure

Found a vulnerability? We want to hear from you.

Security researchers make the whole ecosystem safer. If you've found a potential vulnerability in merlon, we'd genuinely like to know — and we'll work with you in good faith to understand and fix it. This page sets out our scope, the rules, our safe-harbor commitment, and how to reach the team.

Safe harbor for good faith Acknowledged within 2 days
.well-known/security.txt RFC 9116
Contact:mailto:security@merlon.ch
Encryption:https://merlon.ch/pgp-key.txt
Policy:https://merlon.ch/security-disclosure
Preferred-Languages:en
Canonical:https://merlon.ch/.well-known/security.txt
Expires:2026-12-31T23:59:59Z
PGP fingerprint
9F2C 4A7B E1D8 6C03
B54F 2A19 7D6E 8C1B 3F02 A9D4
Copy fingerprint
Our position

Coordinated disclosure makes everyone safer

"We'd rather hear about a flaw from a researcher than from an attacker. A report is a gift — and we treat it like one."

merlon runs two in-house security teams and gates every release, but no program catches everything. External researchers see our systems with fresh eyes and different tools, and that perspective is genuinely valuable to us. This policy exists to make it easy and safe to tell us what you've found — with clear scope, a good-faith safe harbor, and committed response times — so a potential problem becomes a fixed one before anyone is harmed.

Scope

What's in scope — and what isn't

Please focus your testing on the systems below. Anything outside this list is out of scope and may cause harm to us or third parties.

In scope

  • merlon.ch and its authenticated web application
  • The public API (api.merlon.ch, regional endpoints)
  • Authentication, session, and access-control logic
  • Data isolation between tenants and vaults
  • Injection, SSRF, RCE, and similar high-impact classes

Out of scope

  • Denial-of-service or volumetric load testing
  • Social engineering of staff, customers, or vendors
  • Physical attacks against offices or data centres
  • Third-party services and sub-processors we don't control
  • Reports from automated scanners with no demonstrated impact
Rules & safe harbor

Test in good faith, and we've got your back

If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorised, will not pursue or support legal action against you, and will work with you to understand and resolve the issue quickly.

Respect privacy

Only interact with accounts you own or have explicit permission to test. Never access, modify, or exfiltrate other customers' data.

Minimise impact

Stop as soon as you've demonstrated a vulnerability. Don't degrade the service, and don't run destructive or high-volume tests.

Give us time

Report promptly and privately, and allow a reasonable period to remediate before any public disclosure.

Stay lawful

Don't violate any law, and don't use findings for extortion. Safe harbor covers good-faith research within this policy.

How to report

Getting your report to us

Send us enough detail to reproduce the issue. Encrypted reports are welcome using our PGP key.

Email the team

Write to security@merlon.ch with a clear title, affected component, and impact.

Encrypt if sensitive

For sensitive details, encrypt with our PGP key (fingerprint below). The key is published at the Encryption: URL in our security.txt.

Include repro steps

Provide steps to reproduce, a proof-of-concept, and any logs or screenshots that help us confirm quickly.

PGP fingerprint
9F2C 4A7B E1D8 6C03 B54F 2A19 7D6E 8C1B 3F02 A9D4
security.txt
/.well-known/security.txt (RFC 9116)
Preferred language
English

What a good report looks like

Title: Reflected XSS in document search. Component: app.merlon.ch, /search parameter q. Impact: arbitrary script execution in a victim's session. Repro: 1) log in, 2) navigate to search, 3) submit payload <svg onload=…>, 4) observe execution. Suggested fix: output-encode the reflected parameter. Clear, reproducible, and impact-focused — that's all we need.

Our commitment

What you can expect from us

Target timelines from the moment we receive a valid report. We'll keep you updated at each stage.

StageTarget timeWhat happens
AcknowledgementWithin 2 business daysWe confirm receipt and assign a handler.
Triage & validationWithin 5 business daysWe reproduce, assess severity, and confirm scope.
Resolution targetRisk-basedCritical issues prioritised; timeline shared with you.
Closure & thanksOn fix / mitigationWe confirm the fix and, with consent, add you to our thanks.
<2days
Acknowledgement
business days
<5days
Triage
business days
Risk-based
Resolution
severity-driven
Good faith
Safe harbor
for researchers
Coordination

How we work together on a fix

Good disclosure is a two-way street. Here's what we commit to, and what we ask of you, once a report is in.

What we'll do

  • Acknowledge your report within two business days
  • Keep you updated as we triage and remediate
  • Not pursue legal action for good-faith research
  • Credit you publicly, with your consent

What we ask of you

  • Give us reasonable time to fix before disclosing
  • Avoid accessing or altering others' data
  • Keep report details confidential until resolved
  • Never use a finding for extortion or gain
Severity & priority

How we prioritise

We assess severity by real-world impact and exploitability, not by report volume. A rough guide:

Critical
Remote code execution, cross-tenant data access, authentication bypass, or mass data exposure. Prioritised immediately.
High
Privilege escalation, significant access-control flaws, or injection with meaningful impact.
Medium
Issues requiring specific preconditions or limited impact — e.g. stored XSS in a constrained context.
Low / informational
Best-practice deviations with minimal exploitability. We still appreciate the heads-up.
Recognition

Hall of thanks

We don't run a paid bug bounty — our program is recognition-based. With your consent, we're glad to credit researchers who help us improve. Contributions to date are listed anonymously below.

Researcher #001
Researcher #002
Researcher #003
Researcher #004
Researcher #005
You?

Recognition, not a bounty

We do not offer monetary rewards. Our recognition-based program credits researchers publicly (with consent) and prioritises a fast, respectful, collaborative resolution.

Questions

Disclosure questions

Do you pay for vulnerabilities?
No — we run a recognition-based program, not a paid bounty. We credit researchers publicly with their consent and resolve issues quickly and respectfully.
Am I protected legally if I test?
Yes, under our safe harbor — provided you make a good-faith effort to follow this policy, stay in scope, and avoid harm. See Rules & safe harbor above.
How do I encrypt my report?
Use our PGP key, published at the Encryption: URL in our security.txt. The fingerprint is listed in the How to report section.
When will you respond?
We acknowledge valid reports within two business days and complete triage within five. Resolution timing is risk-based, and we keep you updated throughout.

Ready to report?

Send your findings to our security team. We'll acknowledge within two business days and take it from there.

Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more