Marlee Vulnerability Disclosure Program (VDP)
⚠️ Important Notice — No Bug Bounty Program
Marlee maintains a Vulnerability Disclosure Program (VDP) for responsible security reporting.
We do not run a bug bounty program and do not provide financial compensation for vulnerability reports.
Valid reports may be acknowledged through our Hall of Thanks or occasional non-monetary recognition.
Program Scope and Expectations
Marlee operates a limited-scope Vulnerability Disclosure Program intended for responsible disclosure of high-impact security vulnerabilities affecting our platform.
Due to the volume of submissions we receive, we are only able to review reports that demonstrate clear security impact and reproducible exploitation affecting Marlee systems.
Reports consisting of automated scanner output, theoretical vulnerabilities, or general security recommendations may not receive a response.
1. Introduction
At Marlee, we take the security and privacy of our users seriously. We value the work of the security research community and encourage responsible disclosure of any potential vulnerabilities that could impact our platform, users, or data.
This Vulnerability Disclosure Program (VDP) outlines how to report potential security issues safely and responsibly — and how we commit to handling them.
2. Our Commitment
If you act in good faith and adhere to this policy:
- We will not pursue or support legal action against you for your research activities.
- We will work with you to understand, validate, and remediate the issue promptly.
- We will publicly acknowledge your contribution (if you wish) once the issue is resolved.
3. Scope
The following are in scope for this program:
- *.getmarlee.com and app.getmarlee.com
- *.f4s.com legacy domains
- Our public web application, APIs, and authenticated user experiences
- Mobile apps and integrations we own or operate
Out of scope:
- Third-party services (e.g. payment providers, hosting, analytics)
- Social media accounts
- Denial-of-Service (DoS) or stress tests
- Spam or social engineering targeting Marlee employees or users
- Physical security testing
- Missing security headers without a demonstrated exploit
- Clickjacking on pages without sensitive functionality
- Self-XSS requiring a user to paste code into their own console
- Reports about outdated software versions without a working exploit
- Best-practice recommendations without a security impact
- Rate limiting or brute force concerns without demonstrated impact
- Vulnerabilities affecting third-party services or dependencies not controlled by Marlee
If you’re not sure whether a system or endpoint is in scope, please ask first: security@getmarlee.com
4. What to Report
Please report security vulnerabilities with a demonstrable impact on user data, authentication, authorization, or system integrity.
- Expose personal or confidential data
- Compromise user authentication or authorization
- Allow remote code execution, privilege escalation, or injection
- Enable cross-site scripting (XSS), CSRF, or clickjacking
- Manipulate or interfere with API functionality or data integrity
5. Reporting Guidelines
To submit a report:
- Email security@getmarlee.com with:
- A concise description of the issue
- Steps to reproduce or a non-destructive proof of concept (PoC)
- Impact assessment (what data or functionality could be affected)
- Your contact details and PGP key (optional)
- Please avoid:
- Accessing, modifying, or deleting data that isn’t your own
- Running automated scanners or exploit scripts on production systems
- Sharing details publicly before we resolve the issue
- We may ask for additional details or reproduction steps in a sandbox or test environment.
5.1 Quality of Reports
To help us efficiently triage and resolve vulnerabilities, reports should include clear evidence of a real security impact on Marlee systems.
Submissions must include:
- Clear reproduction steps
- A non-destructive proof of concept, where possible
- Explanation of the security impact
- Reports that consist primarily of:
- Automated vulnerability scanner output
- Generic security best-practice recommendations
- Theoretical or non-exploitable issues may be closed without response.
Reports that do not follow the reporting guidelines may be closed without triage.
6. Our Process
When you report a vulnerability:
- We will acknowledge receipt within 3 business days.
- We will triage and verify the issue.
- We will remediate or mitigate validated issues promptly.
- We will notify you when the issue is resolved.
- We will, if appropriate, include your name or handle in our Hall of Thanks page.
7. Rewards
We currently do not offer monetary bounties. However, we do:
- Recognize valid reports on our Hall of Thanks (with your consent).
- Occasionally offer swag or symbolic gifts for critical findings.
When we establish a formal bug bounty program, it will be announced publicly.
8. Legal Safe Harbour
When conducting vulnerability research under this policy, we consider it authorized if you:
- Comply with this policy and act in good faith;
- Avoid actions that could harm users or services;
- Do not access, modify, or exfiltrate data;
- Do not disrupt or degrade our services.
We will not initiate or support legal action for such good-faith research. This aligns with:
- Australian Criminal Code (Computer Offences, Part 10.7)
- U.S. CFAA “good faith security research” interpretations
- EU / GDPR Recital 49 on network and information security
9. Privacy and Data Protection
If you encounter any personal data during your testing:
- Stop testing immediately.
- Do not save, copy, transmit, or share that data.
- Report the finding and the data exposure to security@getmarlee.com immediately.
We operate globally under GDPR-aligned data protection standards, so all reports involving personal data must be handled confidentially and lawfully.
10. Coordinated Disclosure Timeline
We ask researchers to give us a 14-day disclosure window to validate and remediate before public disclosure.
We may request reasonable extensions depending on issue complexity and risk.
11. Hall of Thanks
We’d like to thank the researchers who have responsibly disclosed vulnerabilities to us.
- David San José Gavilán
- Piyush Kumar Shukla
- 0m3rexe
- Nehan Shah
- King Fahim
- Rose Sabar
- Sanjay Saini
- Rajib Mahmud
- Sarthak Agrawal
12. Contact
If your report involves an immediate or severe risk to customer data, mark the email subject as URGENT SECURITY REPORT.
© 2025 Marlee Australia Pty Ltd.
Marlee operates under the Fingerprint for Success Group and complies with Australian privacy law and GDPR.This policy does not create any contractual or payment obligation between Marlee and any researcher.