Security
Responsible Disclosure
If you believe you found a security issue, avoid accessing data that is not yours, disrupting the service or publicly disclosing the issue before it can be reviewed.
What to include
Provide a concise description, affected URL or component, reproduction steps and impact. Remove credentials, personal data and customer content from the initial report.
Good-faith research
Automated destructive testing, denial-of-service activity, social engineering and physical attacks are outside this guidance. No bounty is promised unless agreed in writing.
Contact path
Use the contact channel published by Key Solutions at marlinvix.com and identify the message as a security report.