Skip to main content

Vulnerability Disclosure Program

We strive to have world-class security with multiple layers of protection ensuring customer data is safe. We value the expertise of the security community and welcome responsible, good-faith disclosures to help us keep our systems secure.

If you believe you have found a security issue in a Meroton product or service, please report it directly to us at security@meroton.com.

Please note: This is a strictly voluntary disclosure program. No monetary rewards or bug bounties will be paid for submissions.

Guidelines for Responsible Disclosure​

To help our security team efficiently review and address your findings, please:

  • Submit a detailed report that includes clear, reproducible steps.
  • Do not submit unverified outputs from automated scanners.
  • Do not engage in activitites that degrade our service or impact other users (such as Denial of Service attacks)

Safe Harbor​

Meroton remains committed to protecting those who help us protect our users. Good faith efforts at preventing service degradation, user data loss, and privacy violations are indemnified from legal action from Meroton as part of this program.

Meroton reserves the sole right to determine whether an activity constitutes genuine good faith research. Activities that exploit vulnerabilities for personal gain, unnecessarily compromise user privacy, or intentionally disrupt our systems will not be protected under this policy.