Reporting a security issue
If you have found a vulnerability in one of our services, we would rather hear it from you than read about it later. Write to support@meridianwealth.tech.
What to expect
- We aim to acknowledge a report within a few business days.
- We will tell you what we found and when it is fixed.
- We will not pursue you for a good-faith report made under the guidelines below.
- We do not run a bug bounty and cannot offer payment. This is a small company; the acknowledgement is genuine and the money is not there.
In scope
- meridianwealth.tech — this site.
- accounts.meridianwealth.tech — the identity service: sign-in, two-factor enrolment, token issuance.
- admin.meridianwealth.tech — the administrative console.
Findings in the products themselves — RetireMexicoHub, Forecastly — are welcome at the same address and will be routed to the right place.
Please do not
- Run automated scanners that generate significant load, or attempt denial of service.
- Access, modify or retain data belonging to anyone but yourself. If you can demonstrate an issue without touching someone else's data, do that instead.
- Use social engineering against our staff or customers.
- Disclose publicly before we have had a reasonable chance to fix it.
A note on what we already publish
Some things that look like findings are deliberate. The identity service publishes its signing keys at accounts.meridianwealth.tech/.well-known/jwks.json and its configuration at /.well-known/openid-configuration — both are public by design, because that is how relying parties verify tokens. Those are public keys; the private halves never leave the server.
Machine-readable contact details are at /.well-known/security.txt.