Found a weakness?
Tell us first.
Our commitment
If you discover a vulnerability in Mardenic systems and report it responsibly under this policy, Mardenic will work with you, not against you.
Scope
In scope
- mardenic.com and its public pages.
- Public endpoints explicitly used by mardenic.com.
- Authentication, session, or data-exposure issues on explicitly public Mardenic services.
Out of scope
- Denial of service, resource exhaustion, social engineering, phishing, or physical attacks.
- Private bots, internal R&D systems, employee accounts, local infrastructure, and non-public endpoints.
- Third-party platforms and scanner output without demonstrated impact.
Current public surface
Mardenic.com currently publishes static company, research, and policy pages. It does not provide a public AI or data-upload interface. If that changes, this policy will be updated before the new service enters scope.
How to report
Email support@mardenic.com with subject SECURITY. Include the affected location, minimal reproduction steps, likely impact, and a way to reach you.
Rules of engagement
- Do not access, alter, retain, or delete data that is not yours.
- Test only as much as needed to show the issue.
- Do not degrade service or affect other users.
- Give Mardenic reasonable time to fix the issue before disclosure.
Response and safe harbor
Mardenic aims to acknowledge reports within three business days and communicate honestly about validity, severity, and remediation. Good-faith research within this policy is considered authorized. Safe harbor does not cover data theft, disruption, extortion, or conduct outside this policy. Mardenic currently offers no paid bounty.