VULNERABILITY DISCLOSURE POLICY

(version: 29.09.2026)

SCOPE OF THE POLICY
The Policy applies exclusively to systems, services, and products belonging directly to the Company.
  1. Systems covered by the Policy:
    • main domain and subdomains: *.mruki.com,
    • all officially published applications,
    • official APIs.
  2. Systems not covered by the Policy:
    • services and tools from third-party providers (SaaS) used by the Company,
    • physical infrastructure and sociotechnical methods (e.g., phishing).
SAFE TESTING PRINCIPLES
The activity is expected to be verified in a responsible manner. Actions that could disrupt service continuity or compromise user privacy are prohibited.
It is prohibited to:
  • deleting, modifying, and downloading other users' data (If you gain access to other users' data, immediately stop testing and report the incident),
  • launching DoS/DDoS (Denial of Service) attacks,
  • aggressive automated scanning that generates massive digital traffic,
  • exploitation of the discovered vulnerability for the purpose of blackmail or extortion.
The Company reserves the right to take appropriate action against anyone violating the above prohibitions.
VULNERABILITY REPORTING
Upon discovering a security vulnerability, please submit a report to the address security@mruki.com. At the same time, we ask that you keep the details of the vulnerability confidential for a period of 90 days from the time of reporting, to allow us time to implement fixes.
For confidential submissions, the use of PGP key encryption is recommended.
INFORMATION CONTAINED IN THE REPORT
The report should contain the following information:
  1. the name of the vulnerable product/component along with the application version, or the service URL,
  2. a detailed description of the steps required to reproduce the error,
  3. potential impact of the vulnerability on system security.
SAFE HARBOR
In exchange for compliance with the above rules, the Company undertakes to:
  1. refraining from taking legal action against the reporting person, provided they acted in accordance with this policy,
  2. confirmation of each submission,
  3. keeping the person who submitted the report regularly informed about the status of work on fixing the vulnerability.
REACTION TIME