Security and responsible disclosure

How to report a vulnerability, and what Merki commits to in return.

Quick path

  1. Email security@merki.dev with impact, reproduction, and affected endpoint.
  2. Do not publish before a fix or 90 days, whichever comes first.
  3. Expect acknowledgment within 2 business days.

Details

TopicDecision
Contactsecurity@merki.dev. Abuse (not vulnerabilities): abuse@merki.dev. See the Acceptable use policy.
Scopeapi.merki.dev, status.merki.dev, key handling, verification challenges, caching isolation. BYOK provider internals are out of scope — report those to the provider.
Safe harborGood-faith research that stays in scope, avoids data access beyond proof, and follows this policy is not pursued. Do not exfiltrate, do not degrade service, do not touch other accounts.
HandlingTriage on receipt; severity under CVSS; fix-first for critical; coordinated disclosure with credit if you want it.
What Merki does anywayAutomatic revocation of exposed keys, per-account cache isolation, encryption in transit and at rest. See API keys and Zero data retention.

Checklist

  • [ ] Report includes steps to reproduce and observed vs expected.
  • [ ] No customer data was accessed or retained during research.
  • [ ] Disclosure waits for the fix or the 90-day window.

Next step

Key hygiene for everyone: API keys.