1. Purpose
Security is a craft we take seriously. If you believe you have discovered a vulnerability affecting Merlon infrastructure or services, we want to hear about it. This page describes how to report it and what you can expect from us in return.
2. Scope
In scope:
- Web properties under
merlon-security.euand its subdomains. - Public-facing infrastructure operated by Merlon.
Out of scope:
- Third-party services, vendors or platforms not operated by us.
- Social engineering of staff, clients or partners.
- Physical attacks against offices, staff or hardware.
- Denial-of-service, volumetric or resource-exhaustion testing.
- Reports based solely on automated scanner output without demonstrated impact.
3. How to report
Email security@merlon-security.eu. Please write in English or Dutch. If you require encrypted communication, mention this in your initial message and we will arrange a key exchange.
4. What to include
- A clear description of the issue and its impact.
- The affected URL, asset or component.
- Step-by-step reproduction instructions, including any payloads.
- Your assessment of severity and, if you have one, a suggested mitigation.
- Whether you would like to be credited after resolution.
5. Our commitments
- We will acknowledge your report promptly, typically within a few business days.
- We will investigate in good faith and keep you informed of meaningful progress.
- We will not pursue legal action against researchers acting in good faith within the scope above.
- We will credit you publicly after resolution if you wish.
6. Safe harbour
Research conducted in good faith and within the scope above is considered authorised. We will not initiate or support legal action against you for accidental, good-faith violations of this policy. This safe harbour does not extend to activity that intentionally harms users, exfiltrates data beyond what is necessary to demonstrate the issue, or violates the privacy of third parties.
7. Coordinated disclosure
We follow a coordinated disclosure model. Our default timeline is up to 90 days from the date a valid report is acknowledged, after which the finding may be disclosed publicly. We are happy to agree on a shorter or longer window where it materially helps users.