Marya Labs / Legal

Legal document

Vulnerability Disclosure Policy

Found a security problem? Email support@maryalabs.io with the details. If you research in good faith within the boundaries below, we will not pursue legal action against you, we will keep you informed, and we will credit you if you want.

Last updated 27 August 2026 · Governed by the laws of England and Wales

Contents

  1. 01How to report
  2. 02What to expect from us
  3. 03Safe harbour
  4. 04Scope
  5. 05Rules of engagement
  6. 06We cannot pay

01How to report

Email support@maryalabs.io with "Security" in the subject line. There is no portal and no form to fill in.

A useful report includes:

  • What the issue is and why it matters.
  • Steps to reproduce it, in enough detail that we can follow them.
  • The version, operating system, and configuration you tested.
  • Any proof of concept, log excerpt, or screenshot.
  • Whether you intend to disclose publicly, and when.

Please report in English, and please do not include real personal data belonging to anyone else in your report.

02What to expect from us

Acknowledgement
Within 5 working days.
Initial assessment
Within 10 working days, with our view of severity and what we plan to do.
Progress updates
At least every 14 days while we are working on it.
Fix
As quickly as we reasonably can. Critical issues take priority over everything else.
Credit
We will name you in the release notes if you want to be named, or keep you anonymous if you prefer.

A realistic expectation

We are a very small studio without a dedicated security team or an on-call rotation. We take reports seriously and we will not ignore you, but we cannot promise the response times a larger organisation could. If you have not heard from us in 10 working days, please chase — something has gone wrong with our email, not with our intentions.

03Safe harbour

If you make a good-faith effort to comply with this policy, we will:

  • not bring or support a legal claim against you in connection with your research;
  • not report you to law enforcement in respect of it;
  • treat your research as authorised conduct for the purposes of the Computer Misuse Act 1990;
  • work with you if a third party takes action, to make clear your research was authorised by us.

This applies to systems and software we control. We cannot give safe harbour for testing against anyone else’s infrastructure — including our hosting provider or the AI providers DAWN connects to. Do not test them under this policy.

If you are unsure whether something is in scope, ask us before you test.

04Scope

In scope

  • The maryalabs.com website and its API endpoints.
  • The DAWN plugin and desktop application, including its local services and how they authenticate.
  • The MeterStack plugin.
  • Our software distribution — the installers, and their signing.

Out of scope

  • Third-party services, including our hosting provider and any AI provider.
  • Ableton Live, macOS, and third-party plugins. Report those to their vendors.
  • Social engineering of us or anyone else.
  • Physical attacks, and denial of service or volumetric testing.
  • Reports produced solely by an automated scanner, with no demonstrated impact.
  • Missing security headers, or weak configurations, with no demonstrated exploit path.
  • Vulnerabilities requiring an already fully compromised machine or physical access to it.
  • Documented design decisions. DAWN’s shell and AppleScript lanes are unsandboxed by design and this is disclosed in the EULA and the Security Overview. A report that DAWN can run commands is not a vulnerability. A way to make it run commands *without the user’s involvement, or bypassing a confirmation gate or the kill switch,* very much is — please report that.

05Rules of engagement

While researching, please:

  • Use only your own accounts and test data.
  • Stop as soon as you have confirmed a vulnerability. Do not pivot further into a system.
  • Do not access, modify, or delete data belonging to anyone else. If you encounter someone’s personal data, stop, do not save it, and tell us.
  • Do not degrade our service, and do not run high-volume automated testing against it.
  • Do not disclose publicly until we have had a reasonable chance to fix the issue.

On timing: we ask for 90 days before public disclosure, or until a fix ships, whichever is sooner. If we are being slow or unresponsive, tell us you intend to disclose and we will not treat that as a breach of this policy. Coordinated disclosure is a two-way commitment.

06We cannot pay

We do not run a bug bounty and cannot offer payment. Our products are free and we are a small studio without a security budget.

What we can offer is a genuine response, a fix, public credit if you want it, and our thanks. If a paid bounty is what you are looking for, we would rather say so plainly than waste your time.

Questions about this document? Email support@maryalabs.io.

See all documents in the legal index.

ML / DAWN · SYSTEM FOOTER NETWORK STABLE
Primary system

DAWN BY MARYA LABS

A first-of-its-kind AU/VST3 plugin with an AI agent inside it. It works Ableton Live and your Mac for you, while you keep the creative call.

Public beta · AU / VST3 · macOS
Explore
  • Capabilities↗
  • Provider Ecosystem↗
  • Autonomy & Trust↗
  • Provider Choice↗
  • DAWN Changelog↗
  • MeterStack Page↗
Access
  • Download DAWN↗
  • Download MeterStack↗
  • Support↗
  • support@maryalabs.io↗

Subscribe

Quiet DAWN beta notes and important release updates.

We use your address only to send these updates. Unsubscribe any time. See our Privacy Policy.

© 2026 Marya Labs
Terms·DAWN EULA·Privacy·Cookies·All legal
DAWN · An AI agent in your plugin slot.