Security and disclosure discipline are part of how Mergetic® is built. This page explains how to report a vulnerability and summarises how we protect information.
Found a security issue? Please email security@mergetic.com with enough detail to reproduce it. We will acknowledge, investigate, and keep you informed. Please give us reasonable time to remediate before any public disclosure.
Responsible disclosure
We welcome reports from the security research community. When investigating, please act in good faith, only test against your own enquiries or accounts, avoid privacy violations and service disruption, and never access, alter, or exfiltrate data that is not yours. Research conducted in line with this policy will not be pursued by us as a breach of our terms.
- Do not run automated scanning that degrades the service.
- Do not access, modify, or delete data belonging to others.
- Do not publicly disclose a vulnerability until we have had a reasonable opportunity to remediate.
How we protect information
- The website is served exclusively over HTTPS.
- Security headers (frame-deny, content-type, referrer policy) are applied site-wide.
- Enquiry data is minimised, access-controlled, and retained only as long as needed — see the Privacy Notice.
- Product evidence records are hash-chained (SHA-256) and replayable — tamper-evident by construction — and can be held on WORM storage where records regulation requires it.
- Confidential product detail is disclosed only under a signed non-disclosure agreement, logged and gated by tier.
Scope
This page concerns the public website, mergetic.com. Security of the Mergetic® product platform is addressed separately with customers under contract.
Contact: security@mergetic.com
← Back to mergetic.com