Home About Research

Found a weakness? Tell us before anyone else.

Version 2026-07-13. Mardenic values the work of security researchers and welcomes reports made in good faith.

Our Commitment

Security and safety failures in AI systems are found faster when researchers have a clear, safe way to report them. If you discover a vulnerability in Mardenic's systems and report it responsibly under this policy, Mardenic will work with you, not against you.

Scope

In scope

  • mardenic.com and its pages.
  • The public status endpoint as used by mardenic.com.
  • Authentication, session handling, or data exposure issues only on a Mardenic-operated service that is explicitly made public.

Out of scope

  • Denial-of-service, volumetric, or resource-exhaustion testing.
  • Social engineering, phishing, or physical attacks against Mardenic or its users.
  • Private bots, internal R&D systems, employee accounts, local training infrastructure, and non-public endpoints.
  • Third-party platforms Mardenic uses but does not operate (report those to the vendor).
  • Automated scanner output with no demonstrated impact.

Model Safety Issues

If Mardenic explicitly releases a public AI interface, this policy will also cover model behavior on that interface. Reportable model safety issues would include:

  • Prompt injection that causes an AI system to ignore its operating rules or act on untrusted instructions.
  • Jailbreaks that produce content the Acceptable Use policy prohibits.
  • Extraction of internal prompts, secrets, keys, or protected operational instructions.
  • Leakage of another user's data through model responses.

If you find a way to make an AI system misbehave, demonstrate it minimally and report it. Do not use it, publish it, or build on it while the report is open.

How to Report

Email support@mardenic.com with the subject line SECURITY. Include:

  • What you found and where (URL, endpoint, or prompt).
  • Steps to reproduce, kept as minimal as possible.
  • The impact you believe it has.
  • How to reach you for follow-up.

Rules of Engagement

  • Do not access, modify, or delete data that is not yours. If you encounter someone else's data, stop and report immediately.
  • Test only to the minimum extent needed to demonstrate the issue.
  • Do not degrade the service for other users.
  • Do not retain copies of data obtained during testing beyond what the report requires.
  • Give Mardenic reasonable time to fix the issue before any public disclosure.

What to Expect

  • Acknowledgment of your report within three business days.
  • Honest communication about validity, severity, and fix timeline.
  • Credit for the finding if you want it, once the issue is resolved.

Mardenic does not currently operate a paid bounty program.

Safe Harbor

Research conducted in good faith and in line with this policy is considered authorized. Mardenic will not pursue legal action against researchers for such activity and will say so if a third party asks. This safe harbor does not cover actions outside this policy, including data theft, service disruption, or extortion.