MERSAL24
SECURITY

Vulnerability Disclosure Policy

MERSAL24 takes the security of our website, systems, and customer information seriously. We appreciate responsible security researchers who help us identify and resolve potential vulnerabilities.

How to report a security issue

If you believe you have discovered a security vulnerability affecting MERSAL24, please contact us at security@mersal24.com.

Please include, where possible, a clear description of the issue, the affected URL or service, steps to reproduce it, supporting screenshots or evidence, and the potential security impact.

Please do not include unnecessary personal, confidential, or customer information in your report.

Scope

This policy applies to MERSAL24-controlled public web services, including:

  • https://mersal24.com
  • https://www.mersal24.com

Third-party services and infrastructure not directly controlled by MERSAL24, including hosting, email, domain-registration, and SaaS providers, are outside the scope of this policy unless explicitly stated otherwise.

Responsible testing

When conducting security research, please use the minimum testing necessary to demonstrate the issue and:

  • Avoid disrupting MERSAL24 services or availability.
  • Do not perform denial-of-service or load-testing attacks.
  • Do not use social engineering, phishing, or physical attacks.
  • Do not access, modify, download, or delete information belonging to other users.
  • Do not attempt to obtain passwords, authentication tokens, or credentials beyond what is necessary to demonstrate a vulnerability.
  • Stop testing immediately if you encounter confidential or personal information.
  • Do not publicly disclose a vulnerability before MERSAL24 has had a reasonable opportunity to investigate and remediate it.

Our response

We will make reasonable efforts to acknowledge legitimate reports, investigate reported vulnerabilities, keep researchers informed when appropriate, and address validated issues based on their severity and impact.

Response and remediation times may vary depending on the complexity and severity of the issue.

Bug bounty

MERSAL24 does not currently operate a public bug bounty program. Submitting a vulnerability report does not create an entitlement to compensation unless a reward has been explicitly agreed to in writing.

Privacy

Information submitted through our security reporting process will be used to investigate, validate, and remediate security issues.

REPORT A VULNERABILITY

Security contact

security@mersal24.com