Data safety and service integrity are our absolute priorities. We highly value the contributions of security researchers in helping protect our ecosystem.
Who We Are
Our website address is https://mersal.it.
Mersal is a multi-channel bulk-messaging and marketing-automation platform — SMS, WhatsApp, and Email campaigns, CRM, automation, and AI tools — operated from Cairo, Egypt.
You can reach us any time at [email protected].
1. Our Commitment to Cybersecurity
Mersal uses HTTPS/TLS encryption and database protections to secure webhook channels, API requests, and user details. Continuous automated scanning and vulnerability checks defend our infrastructure.
2. Responsible Disclosure Guidelines
- Private submission: send details directly and confidentially to [email protected].
- Data minimization: do not exploit a bug to view, extract, or delete other users’ data.
- No public disclosure: avoid publishing details until Mersal has remediated the issue.
3. Safe Harbor
Mersal pledges not to pursue legal action against researchers who act in good faith, respect user privacy, and fully comply with this policy.
4. Response & Remediation
- Acknowledging receipt and providing an initial review within 48 hours.
- Determining a remediation timeline based on severity and keeping you updated.
- Offering official gratitude to researchers whose verified reports strengthen Mersal’s safety.
5. Strictly Prohibited Testing Actions
- Executing denial-of-service (DoS/DDoS) attacks.
- Brute force or automated password spraying against customer portals.
- Social engineering, phishing, or physical attacks on Mersal infrastructure and personnel.