Responsible Disclosure
Marbleland Labs welcomes good-faith security research intended to improve the security of our systems and users. Please report suspected vulnerabilities privately before public disclosure.
How to Report
Email security@marbleland.io with a clear description of the issue, affected component, reproduction steps, potential impact and any relevant screenshots or logs. Do not include real user secrets unless necessary and authorized.
Good-Faith Research Expectations
- Avoid privacy violations, data destruction, service disruption and social engineering.
- Use the minimum testing necessary to demonstrate the issue.
- Do not access or retain data belonging to other users beyond what is strictly necessary to document the vulnerability.
- Allow reasonable time for investigation and remediation before public disclosure.
Out of Scope
Examples that may be out of scope include purely theoretical issues without security impact, clickjacking on non-sensitive pages, rate-limit observations without exploitability, self-XSS, and findings that require compromised user devices unless they reveal a separate Marbleland vulnerability.
Response and Coordination
We aim to acknowledge actionable reports and coordinate remediation in good faith, but response times may vary by severity and operational circumstances. No bounty or payment is promised unless a separate program expressly states otherwise.
Security Contact
Security reports: security@marbleland.io. General support: support@marbleland.io.