Legal document
Vulnerability Disclosure Policy
Found a security problem? Email support@maryalabs.io with the details. If you research in good faith within the boundaries below, we will not pursue legal action against you, we will keep you informed, and we will credit you if you want.
Last updated 27 August 2026 · Governed by the laws of England and Wales
01How to report
Email support@maryalabs.io with "Security" in the subject line. There is no portal and no form to fill in.
A useful report includes:
- What the issue is and why it matters.
- Steps to reproduce it, in enough detail that we can follow them.
- The version, operating system, and configuration you tested.
- Any proof of concept, log excerpt, or screenshot.
- Whether you intend to disclose publicly, and when.
Please report in English, and please do not include real personal data belonging to anyone else in your report.
02What to expect from us
- Acknowledgement
- Within 5 working days.
- Initial assessment
- Within 10 working days, with our view of severity and what we plan to do.
- Progress updates
- At least every 14 days while we are working on it.
- Fix
- As quickly as we reasonably can. Critical issues take priority over everything else.
- Credit
- We will name you in the release notes if you want to be named, or keep you anonymous if you prefer.
03Safe harbour
If you make a good-faith effort to comply with this policy, we will:
- not bring or support a legal claim against you in connection with your research;
- not report you to law enforcement in respect of it;
- treat your research as authorised conduct for the purposes of the Computer Misuse Act 1990;
- work with you if a third party takes action, to make clear your research was authorised by us.
This applies to systems and software we control. We cannot give safe harbour for testing against anyone else’s infrastructure — including our hosting provider or the AI providers DAWN connects to. Do not test them under this policy.
If you are unsure whether something is in scope, ask us before you test.
04Scope
In scope
- The maryalabs.com website and its API endpoints.
- The DAWN plugin and desktop application, including its local services and how they authenticate.
- The MeterStack plugin.
- Our software distribution — the installers, and their signing.
Out of scope
- Third-party services, including our hosting provider and any AI provider.
- Ableton Live, macOS, and third-party plugins. Report those to their vendors.
- Social engineering of us or anyone else.
- Physical attacks, and denial of service or volumetric testing.
- Reports produced solely by an automated scanner, with no demonstrated impact.
- Missing security headers, or weak configurations, with no demonstrated exploit path.
- Vulnerabilities requiring an already fully compromised machine or physical access to it.
- Documented design decisions. DAWN’s shell and AppleScript lanes are unsandboxed by design and this is disclosed in the EULA and the Security Overview. A report that DAWN can run commands is not a vulnerability. A way to make it run commands *without the user’s involvement, or bypassing a confirmation gate or the kill switch,* very much is — please report that.
05Rules of engagement
While researching, please:
- Use only your own accounts and test data.
- Stop as soon as you have confirmed a vulnerability. Do not pivot further into a system.
- Do not access, modify, or delete data belonging to anyone else. If you encounter someone’s personal data, stop, do not save it, and tell us.
- Do not degrade our service, and do not run high-volume automated testing against it.
- Do not disclose publicly until we have had a reasonable chance to fix the issue.
On timing: we ask for 90 days before public disclosure, or until a fix ships, whichever is sooner. If we are being slow or unresponsive, tell us you intend to disclose and we will not treat that as a breach of this policy. Coordinated disclosure is a two-way commitment.
06We cannot pay
We do not run a bug bounty and cannot offer payment. Our products are free and we are a small studio without a security budget.
What we can offer is a genuine response, a fix, public credit if you want it, and our thanks. If a paid bounty is what you are looking for, we would rather say so plainly than waste your time.