marshal ·  emefa LLC

Vulnerability Disclosure Policy

marshal, built by emefa LLC, welcomes reports from security researchers. If you believe you have found a security vulnerability in our app or services, we want to hear from you and will work with you to resolve it.

Last updated: July 20, 2026

How to report a vulnerability

Email security@emefa.us. We aim to acknowledge your report within 3 business days and to keep you updated as we investigate.

Please include: a description of the issue and its potential impact, the steps to reproduce it (proof-of-concept, affected URL/screen, request/response where relevant), and your name or handle if you would like to be credited.

We do not offer monetary rewards for vulnerability reports. marshal does not operate a paid bug-bounty program; recognition is by credit on our Security Acknowledgments page on request.

Scope

In scope:

Out of scope (please do not test these):

Safe harbor

emefa LLC will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. We consider such research to be authorized under applicable law (and equivalent laws in other jurisdictions), and:

To stay within this safe harbor, please: only interact with accounts you own or have explicit permission to test; never access, modify, or delete another person’s data; do not degrade or interrupt the service for others; stop and report immediately if you encounter personal data (and redact or minimize any you must include in a report); give us reasonable time to remediate before any public disclosure; and, if you are unsure whether a target or technique is authorized, email security@emefa.us before proceeding. This safe harbor applies only to marshal-operated systems and does not authorize testing of third-party services.

How we respond

Machine-readable contact

Our security contact is also published, per RFC 9116, at /.well-known/security.txt.