Vulnerability Disclosure Policy
Mara welcomes good-faith security research that helps us protect our users and systems. Reports may be written in Arabic or English.
Report privately
Email security@iammara.com. Do not open a public issue or disclose a suspected vulnerability before Mara has had a reasonable opportunity to investigate and remediate it.
Scope
This policy covers systems that Mara owns and operates under iammara.com, including the public website and product API. A hostname being publicly reachable does not authorize disruptive testing.
- Third-party services and infrastructure not operated by Mara are out of scope.
- Social engineering, phishing, physical attacks, and attacks against employees or users are prohibited.
- Do not perform denial of service, load testing, spam, credential stuffing, or automated traffic that could affect availability or cost.
- Do not access, change, download, retain, or share another person's data.
- Scanner output or a missing best-practice header without demonstrated security impact is not sufficient by itself.
If you are unsure whether a test is safe or in scope, email us before proceeding.
Testing rules
- Use only accounts and data you own or have explicit permission to use.
- Use the minimum requests and data needed to demonstrate the issue.
- Do not establish persistence, pivot to other systems, or attempt to extract secrets.
- Stop immediately if you encounter personal, health, financial, or other sensitive data. Do not copy it; tell us what happened.
- Use non-destructive evidence and keep the report confidential while remediation is coordinated.
What to include
Include the affected hostname or component, prerequisites, exact reproduction steps, observed and expected behavior, security impact, and non-destructive evidence. Include a suggested fix if you have one. Do not send real user data or credentials.
Our response
We aim to acknowledge a report within three business days and provide a meaningful status update within seven business days. Remediation time depends on severity and complexity. We will coordinate disclosure timing and credit the reporter if requested and appropriate.
Safe harbor
Mara will not initiate legal action against research conducted in good faith and in compliance with this policy. If an accidental violation occurs, stop testing, avoid further access or use of data, and contact us promptly. This safe harbor does not authorize activity against third parties and cannot bind organizations Mara does not control.
Rewards
Mara does not currently operate a paid bug bounty program. Submitting a report does not create a promise or entitlement to payment. Any recognition or reward is entirely discretionary and must be agreed in writing by Mara.