Security Acknowledgments
We are grateful to the security researchers who help keep marshal and its members safe. This page recognizes those who have responsibly disclosed a vulnerability to emefa LLC.
Last updated: July 21, 2026
No external reports yet — you could be the first
We have not yet received an external vulnerability report. When a researcher responsibly discloses an issue under our Vulnerability Disclosure Policy and consents to be named, we will list them here — with the report date and a short, non-sensitive description of the class of issue, published only after a fix has shipped.
To report a vulnerability, email security@emefa.us and tell us how you would like to be credited (your name or a handle). Details are in our Vulnerability Disclosure Policy.
How we credit researchers
- We list researchers in the order their valid report was received, once a fix has shipped and coordinated disclosure is complete.
- Recognition is at your option — tell us the name or handle you would like shown, or ask to remain anonymous, and we will honor that request.
- We publish only what is safe to share: the class of issue and the report month, never reproduction details or anything that could identify affected members.
- marshal does not currently operate a paid bug-bounty program. Recognition on this page is our thanks for helping protect our members.
Ongoing internal review
Alongside external disclosures, marshal's code is reviewed through recurring internal adversarial security review before each release milestone — covering authentication and authorization, tenant isolation, data-privacy handling, and our records-retention model. External reports remain the most valuable check we have, which is why we maintain a clear disclosure and safe-harbor policy and respond to every good-faith report.
A record of the standards and references that inform our reviews is maintained internally and shared with counsel and partners on request.
Machine-readable contact
Our security contact and this acknowledgments page are published, per RFC 9116, at /.well-known/security.txt.