Vulnerability Disclosure Policy
marshal, built by emefa LLC, welcomes reports from security researchers. If you believe you have found a security vulnerability in our app or services, we want to hear from you and will work with you to resolve it.
Last updated: July 20, 2026
How to report a vulnerability
Email security@emefa.us. We aim to acknowledge your report within 3 business days and to keep you updated as we investigate.
Please include: a description of the issue and its potential impact, the steps to reproduce it (proof-of-concept, affected URL/screen, request/response where relevant), and your name or handle if you would like to be credited.
We do not offer monetary rewards for vulnerability reports. marshal does not operate a paid bug-bounty program; recognition is by credit on our Security Acknowledgments page on request.
Scope
In scope:
- The marshal web application at marshalapp.us.
- The marshal iOS and Android apps (com.emefa.marshal).
- The marshal backend operated by emefa LLC.
Out of scope (please do not test these):
- Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks.
- Social engineering, phishing, or physical attacks against emefa LLC, its staff, or its users.
- Vulnerabilities in third-party services we build on (e.g. Google Firebase, LiveKit, Stripe) — report those to the respective vendor; we are happy to help coordinate.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Missing best-practice hardening (e.g. header tweaks) with no concrete security impact.
Safe harbor
emefa LLC will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. We consider such research to be authorized under applicable law (and equivalent laws in other jurisdictions), and:
- To the extent your good-faith research under this policy would otherwise violate the Digital Millennium Copyright Act (or equivalent anti-circumvention laws), we waive that restriction for activity conducted under this policy.
- We will not bring a claim against you for accidental, good-faith violations of our Terms of Use or Acceptable Use Policy arising from your research under this policy.
- Should legal action be initiated by a third party against you for activities conducted in accordance with this policy, we will make this authorization known.
To stay within this safe harbor, please: only interact with accounts you own or have explicit permission to test; never access, modify, or delete another person’s data; do not degrade or interrupt the service for others; stop and report immediately if you encounter personal data (and redact or minimize any you must include in a report); give us reasonable time to remediate before any public disclosure; and, if you are unsure whether a target or technique is authorized, email security@emefa.us before proceeding. This safe harbor applies only to marshal-operated systems and does not authorize testing of third-party services.
How we respond
- We aim to acknowledge your report within 3 business days and to provide an initial triage and severity assessment within 10 business days.
- We will work to validate and remediate confirmed issues, prioritized by severity, and keep you informed of our progress.
- We practice coordinated disclosure: we ask that you keep details private until a fix is released, targeting coordinated public disclosure within 90 days of your report (or on fix release, whichever is sooner), and we will coordinate with you if more time is needed.
- marshal does not offer monetary rewards for vulnerability reports and does not operate a paid bug-bounty program; we are glad to credit you by name or handle on our Security Acknowledgments page on request.
Machine-readable contact
Our security contact is also published, per RFC 9116, at /.well-known/security.txt.