Security and responsible disclosure
How to report a vulnerability, and what Merki commits to in return.
Quick path
- Email security@merki.dev with impact, reproduction, and affected endpoint.
- Do not publish before a fix or 90 days, whichever comes first.
- Expect acknowledgment within 2 business days.
Details
| Topic | Decision |
|---|---|
| Contact | security@merki.dev. Abuse (not vulnerabilities): abuse@merki.dev. See the Acceptable use policy. |
| Scope | api.merki.dev, status.merki.dev, key handling, verification challenges, caching isolation. BYOK provider internals are out of scope — report those to the provider. |
| Safe harbor | Good-faith research that stays in scope, avoids data access beyond proof, and follows this policy is not pursued. Do not exfiltrate, do not degrade service, do not touch other accounts. |
| Handling | Triage on receipt; severity under CVSS; fix-first for critical; coordinated disclosure with credit if you want it. |
| What Merki does anyway | Automatic revocation of exposed keys, per-account cache isolation, encryption in transit and at rest. See API keys and Zero data retention. |
Checklist
- [ ] Report includes steps to reproduce and observed vs expected.
- [ ] No customer data was accessed or retained during research.
- [ ] Disclosure waits for the fix or the 90-day window.
Next step
Key hygiene for everyone: API keys.