Responsible Disclosure
Meredic operates in regulated environments where security is non-negotiable. We welcome responsible security research and are committed to working openly with researchers who identify vulnerabilities in good faith.
Scope
This policy applies to security vulnerabilities affecting:
- The meredic.com website and any subdomains.
- The Cura application and its backend APIs and endpoints operated by Meredic.
- Publicly exposed APIs or endpoints operated by Meredic.
- Configuration or infrastructure issues that expose non-public data.
This policy does not apply to vulnerabilities in third-party services we use, or to defects in Meredic products deployed within a customer’s private infrastructure — those should be reported through your enterprise support channel.
How to report
Send a written description of the vulnerability to security@meredic.com. Encrypt your report using our PGP key (available on request) if the details are sensitive. Include:
- A clear description of the issue and its potential impact.
- Steps to reproduce, including URLs, payloads, or proof-of-concept code where relevant.
- Your name or handle, and whether you wish to be credited if we publish an advisory.
Our commitments
In exchange for responsible disclosure, Meredic commits to:
- Acknowledge receipt of your report within two business days.
- Provide an initial assessment of severity and planned remediation within ten business days.
- Keep you informed of progress and notify you when the issue is resolved.
- Not pursue legal action against researchers who act in good faith and comply with this policy.
- Credit researchers (with their consent) in any public advisory we issue.
Responsible research guidelines
We ask researchers to:
- Avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate the vulnerability.
- Not perform denial-of-service testing or automated high-volume scanning.
- Not disclose the vulnerability publicly until we have had a reasonable opportunity to remediate it (typically 90 days from acknowledgement, extendable by mutual agreement).
- Not use the vulnerability for personal gain or to access customer data.
Bug bounty
Meredic does not currently operate a formal bug bounty programme with monetary rewards. We may offer recognition and acknowledgement for significant findings at our discretion. We are evaluating a formal programme and will update this policy if one is introduced.
Privacy enquiries: privacy@meredic.com · Security: security@meredic.com
