Introduction
At Marshul, we take the security of our website, customer data, and systems very seriously. We are committed to maintaining a secure online environment and protecting the privacy and safety of our customers. This document outlines how to report security vulnerabilities, data breaches, and other security concerns to Marshul.
If you discover a security issue, we encourage you to report it responsibly and confidentially. Your assistance in identifying and resolving security vulnerabilities helps us protect all Marshul customers.
Types of Security Issues to Report
Marshul welcomes reports of the following types of security issues:
Website Vulnerabilities
•SQL injection vulnerabilities
•Cross-site scripting (XSS) vulnerabilities
•Cross-site request forgery (CSRF) vulnerabilities
•Insecure direct object references
•Security misconfiguration
•Sensitive data exposure
•Broken authentication or session management
•Insecure deserialization
•Using components with known vulnerabilities
•Insufficient logging and monitoring
Account Security Issues
•Unauthorized account access
•Account takeover vulnerabilities
•Weak password requirements
•Session hijacking vulnerabilities
•Insecure password reset mechanisms
•Account enumeration vulnerabilities
Payment Security Issues
•Insecure payment processing
•Unencrypted payment data transmission
•PCI compliance violations
•Credit card data exposure
•Payment processor vulnerabilities
Data Security Issues
•Unencrypted personal data
•Exposed customer information
•Insecure data storage
•Data breach incidents
•Privacy policy violations
•Unauthorized data access
Infrastructure Security Issues
•Server misconfigurations
•Unpatched systems or software
•Exposed databases or backups
•Insecure APIs
•Network vulnerabilities
•Denial of service vulnerabilities
Social Engineering and Phishing
•Phishing emails impersonating Marshul
•Social engineering attacks targeting Marshul
•Fraudulent websites impersonating Marshul
•Malicious content on Marshul properties
How to Report a Security Issue
Responsible Disclosure
We ask that you follow responsible disclosure practices when reporting security issues:
•Report the issue directly to Marshul before disclosing it publicly
•Provide us with reasonable time to investigate and fix the issue
•Do not exploit the vulnerability beyond what is necessary to confirm it
•Do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability
•Do not disrupt or degrade the performance of Marshul systems
•Do not engage in any illegal activities
Reporting Methods
You can report security issues to Marshul using the following methods:
Email (Preferred)
Send a detailed security report to:
Include the following information in your email:
•Your name and contact information
•Description of the security issue
•Steps to reproduce the vulnerability
•Potential impact of the vulnerability
•Any proof-of-concept code or screenshots (if applicable)
•Your preferred method of contact for follow-up
Phone
For urgent security issues, you can call us at:
+1 512 254-3759
Ask to speak with the Security Team. Provide a brief description of the issue and your contact information. We will follow up with you within 24 hours.
Mailing Address
For sensitive security reports, you can mail a detailed report to:
Marshul Security Team
155 Carrasco Ave, Odessa, TX 79763, USA
Include your contact information and a detailed description of the security issue. Mark the envelope as “CONFIDENTIAL – SECURITY REPORT.”
In-Person
If you are in the Odessa, Texas area, you may visit our office during business hours to report a security issue in person. Ask for the Security Team or a manager.
What to Include in Your Report
Essential Information
To help us investigate your report efficiently, please include:
•Issue Title: A brief, clear title describing the security issue
•Issue Description: A detailed explanation of the vulnerability or security concern
•Affected Component: Which part of marshul.com or which system is affected
•Steps to Reproduce: Clear, step-by-step instructions on how to reproduce the issue
•Proof of Concept: Screenshots, videos, or code demonstrating the vulnerability (if applicable)
•Potential Impact: An assessment of the potential impact if the vulnerability were exploited
•Severity: Your assessment of the severity (critical, high, medium, low)
•Your Contact Information: Name, email, phone number, and preferred contact method
Additional Information
If applicable, also provide:
•Browser and operating system information
•Date and time the issue was discovered
•Any previous reports of the same issue
•Suggested remediation or fix (if you have one)
Our Response Process
Initial Acknowledgment
Upon receiving your security report, we will:
•Send you an acknowledgment email within 24 hours
•Assign your report a tracking number
•Provide you with a point of contact for follow-up
Investigation
Our security team will:
•Investigate the reported vulnerability
•Attempt to reproduce the issue
•Assess the severity and impact
•Determine the scope of the vulnerability
•Identify affected systems or data
Investigation typically takes 5-10 business days, depending on the complexity of the issue.
Updates and Communication
We will provide you with regular updates on the status of your report:
•Initial assessment (within 3 business days)
•Investigation progress (weekly updates)
•Resolution timeline (once a fix is identified)
•Deployment confirmation (once the fix is deployed)
Remediation and Fix
Once a vulnerability is confirmed, our team will:
•Develop a fix or remediation plan
•Test the fix thoroughly
•Deploy the fix to production
•Verify that the vulnerability is resolved
Notification
Once the vulnerability is fixed, we will:
•Notify you that the issue has been resolved
•Provide details about the fix
•Thank you for your responsible disclosure
Disclosure Timeline
Responsible Disclosure Period
We ask that you allow Marshul a reasonable amount of time to investigate and fix security issues before public disclosure:
•Critical Issues: 30 days from initial report
•High Severity Issues: 45 days from initial report
•Medium Severity Issues: 60 days from initial report
•Low Severity Issues: 90 days from initial report
If we have not fixed the issue within the agreed-upon timeframe, you may disclose the vulnerability publicly, provided you give us 7 days’ notice before disclosure.
Expedited Timeline
If a vulnerability is being actively exploited or poses an immediate threat, we will prioritize the fix and work to deploy a solution as quickly as possible.
Public Disclosure
Once a fix has been deployed, you are welcome to publicly disclose the vulnerability. We ask that you:
•Provide Marshul with advance notice of your disclosure
•Include information about how the vulnerability was fixed
•Credit Marshul for working with you on the fix
•Avoid disclosing sensitive details that could aid attackers
Confidentiality and Privacy
Confidentiality
All security reports are treated as confidential. We will:
•Not disclose your identity without your permission
•Not share your report with third parties without your consent
•Keep your report confidential during the investigation and remediation process
•Protect your personal information
Privacy
Your contact information will be used only for:
•Communicating about your security report
•Sending you updates on the investigation
•Thanking you for your responsible disclosure
We will not add your email to marketing lists or contact you for other purposes without your permission.
Public Recognition
With your permission, we may publicly acknowledge your contribution to Marshul’s security by:
•Listing your name on a security acknowledgments page
•Mentioning your name in a press release or blog post
•Including your name in security documentation
You can opt out of public recognition by requesting anonymity in your report.
What We Cannot Accept
Marshul cannot accept reports of the following types of issues:
•Brute Force Attacks: We cannot accept reports of brute force vulnerabilities if they are discovered through actual brute force attacks
•Denial of Service: We cannot accept reports of denial of service vulnerabilities discovered through actual denial of service attacks
•Phishing: We cannot accept reports of phishing attacks unless you are reporting phishing emails impersonating Marshul
•Spam: We cannot accept reports of spam or unsolicited emails
•Third-Party Issues: We cannot accept reports of vulnerabilities in third-party services or websites that are not operated by Marshul
•Policy Violations: We cannot accept reports of policy violations that are not security-related
•Theoretical Issues: We cannot accept reports of theoretical vulnerabilities without proof of concept
Legal Protection
No Legal Action
Marshul will not pursue legal action against anyone who:
•Reports a security vulnerability in good faith
•Follows responsible disclosure practices
•Does not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability
•Does not disrupt or degrade Marshul systems
Safe Harbor
This security reporting policy provides a safe harbor for security researchers and ethical hackers who report vulnerabilities responsibly.
Compliance with Laws
While we provide legal protection for responsible security research, you must comply with all applicable laws and regulations. Unauthorized access to computer systems is illegal in most jurisdictions, even for security research purposes.
Rewards and Recognition
Bug Bounty Program
Marshul may offer rewards for security vulnerabilities reported through this program. Rewards are determined based on:
•Severity of the vulnerability
•Impact on customer data or systems
•Quality of the report
•Difficulty of discovering the vulnerability
Recognition
We recognize and appreciate the contributions of security researchers who help improve Marshul’s security. With your permission, we will:
•Thank you publicly for your responsible disclosure
•List your name on our security acknowledgments page
•Mention your contribution in our security reports
Contact Information
Security Reporting
To report a security issue, contact:
Email: security@marshul.com
Phone: +1 512 254-3759
Mailing Address:
Marshul Security Team
155 Carrasco Ave, Odessa, TX 79763, USA
General Inquiries
For general questions about Marshul’s security practices, contact:
Email: contact@marshul.com
Phone: +1 512 254-3759
Website: www.marshul.com
Business Hours
Monday – Friday: 9:00 AM – 6:00 PM (Central Time)
Saturday: 10:00 AM – 4:00 PM (Central Time)
Sunday: Closed
Security Best Practices for Customers
While we work to maintain a secure website, we also encourage our customers to follow these security best practices:
•Use strong, unique passwords for your Marshul account
•Enable two-factor authentication if available
•Do not share your login credentials with anyone
•Be cautious of phishing emails claiming to be from Marshul
•Verify URLs before entering sensitive information
•Keep your browser and operating system updated
•Use antivirus and anti-malware software
•Report suspicious activity immediately
Changes to This Policy
Marshul may update this security reporting policy at any time. Changes are effective immediately upon posting to our website. We will notify security researchers of material changes to this policy.
Appreciation
We appreciate the efforts of security researchers and ethical hackers who help identify and report security vulnerabilities. Your responsible disclosure helps us protect Marshul customers and maintain a secure online environment.
Thank you for your commitment to security and your partnership with Marshul.