Appearance
Vulnerability Disclosure Programme
Effective 4 October 2026.
We encourage responsible reports of vulnerabilities that could affect EasyMerge, its GitHub App, dashboard, or the handling of code and data.
Reporting channel
Send a private report to security@ez-merge.com, with a subject beginning SECURITY:. If you cannot use email, create a Technical ticket in Help & Support with only the minimum information needed for us to contact you. Do not send secrets or an exploitable proof of concept through that ticket: installation members can view it.
This channel is for security reports, not ordinary product support.
What to include
Send a clear description, safe reproduction steps, expected scope or impact, relevant version or URL, and contact details for follow-up. Remove access tokens, personal data, unnecessary source code and other secrets. If sensitive material is needed, ask for an appropriate exchange channel first.
Acceptable research
Test only accounts and data that you own or are expressly authorised to test; minimise testing to avoid affecting users; stop once you have demonstrated the issue; and do not disclose details publicly before we have had a chance to address them.
Do not access, alter, delete or download another person's data; disrupt the service; perform social engineering, phishing, spam or denial-of-service attacks; or exploit a vulnerability beyond the minimum needed to demonstrate it.
Our response
We will acknowledge a report where we can, assess validity and impact, prioritise risk reduction, and share progress through the reporting channel. The beta has no committed response time or bounty. We will give public credit only with your consent and after the risk has been addressed.
This policy does not authorise unlawful conduct, unauthorised access or exemption from legal obligations. For an issue causing active harm, say that it is urgent in the email subject.