Security approach and vulnerability disclosure
This page provides a transparent overview of the security approach for the public SustaTrace marketing and documentation website and explains how suspected security vulnerabilities can be reported.
This page covers the public SustaTrace marketing and documentation website. The SustaTrace SaaS application is a separate service surface and may be subject to separate security controls, contractual commitments, service terms, and customer-specific requirements.
The CarbonX3 Green Chain, Micro Ledger, CX3Scan, and other related ecosystem or infrastructure components are separate systems and are not represented as being covered by the security statements on this page unless expressly stated otherwise.
Where assurance comes from
SustaTrace incorporates security practices and technical controls intended to reduce common risks across the website, its documentation, and its supporting infrastructure.
Security measures may include:
- secure server and application configuration;
- access-control and authentication protections where applicable;
- server-side validation and request handling;
- CSRF protection for applicable forms;
- dependency and infrastructure maintenance;
- controlled handling of contact and demo-request data; and
- monitoring, review, and remediation of reported security issues.
These measures are intended to reduce specific classes of security risk. They do not constitute a security certification, independent security audit, formal verification, or guarantee that the website or any related service is free from vulnerabilities.
Security also depends on third-party infrastructure, dependencies, hosting providers, browser environments, network conditions, user configuration, and other components outside Mersolution's direct control.
Audit and bug bounty status
For transparency, the current security-assurance status is stated explicitly.
-
Third-party security audit
No completed independent third-party security audit report for the public SustaTrace website has been publicly released at this time.
The absence of a published audit should not be interpreted as a claim that the website is free from vulnerabilities.
Where independent security assessments or audits are completed and can be publicly disclosed, relevant information may be published on this page.
-
Public bug bounty programme
There is currently no public bug bounty programme for the public SustaTrace website.
Security researchers who identify a potential vulnerability are encouraged to use the responsible-disclosure channel described below.
-
Source code availability
The source code for the public SustaTrace website and its supporting application components is not currently published as a fully public source repository.
This status may change in the future. Any applicable source-release or repository policy will be reflected on this page.
How to report a security vulnerability
Please report suspected security vulnerabilities to hello@mersolution.com with the subject line:
Security report
Where possible, include:
- a clear technical description of the issue;
- the affected component, endpoint, page, version, or environment;
- reproducible steps or a proof of concept;
- the potential security impact; and
- relevant logs, screenshots, or technical evidence that can be safely shared.
Do not include private keys, recovery phrases, passwords, authentication credentials, API keys, session tokens, or other sensitive secrets in a report.
Responsible disclosure
We ask security researchers to provide Mersolution with a reasonable opportunity to review and address reported vulnerabilities before making technical details publicly available.
Researchers should avoid unnecessary access to, modification of, disruption to, or exfiltration of data and should limit testing to what is reasonably necessary to demonstrate the reported security issue.
Testing should be conducted in a manner that does not intentionally cause service disruption, privacy violations, data loss, or degradation of availability.
Good-faith security research
Mersolution does not intend to pursue legal action solely because a researcher reports a suspected vulnerability in good faith through the designated security channel and conducts testing responsibly.
This statement does not create a contractual authorization for security testing or provide a general or unlimited permission to access systems.
It does not waive or limit applicable law and does not authorize unauthorized access, data theft, privacy violations, service disruption, destruction or alteration of data, denial-of-service activity, or other unlawful conduct.
Researchers remain responsible for complying with applicable law and for limiting their activities to the minimum reasonably necessary to demonstrate the reported vulnerability.
Disclosure, incidents and development transparency
The security programme is being developed incrementally. The information below reflects the current publicly disclosed state.
-
Machine-readable security contact
A
security.txtfile based on RFC 9116 is published at:The file provides the security contact information and a reference to this security page so that security researchers and automated tools can discover the reporting channel.
-
Incident response
Security reports received through the designated channel are reviewed and triaged by the responsible operating team.
There is currently no publicly committed, time-bound incident-response SLA, such as a guaranteed acknowledgement, remediation, or disclosure period.
Any future formal response-time commitments will be published separately.
-
Security updates
Security issues identified through internal review, third-party assessment, responsible disclosure, or operational monitoring may result in patches, configuration changes, dependency updates, infrastructure changes, or other remediation measures.
Where appropriate, material security information may be reflected in future updates to this page.
-
SBOM and secure development
A publicly available Software Bill of Materials (SBOM) and a formal, publicly documented Secure Development Lifecycle (SDL) policy for the public SustaTrace website and its supporting application components are not currently available.
This page will be updated if such materials are formally published.
No complete security guarantee
No software, website, network, or information system can be guaranteed to be completely secure.
The security practices and controls described on this page are intended to reduce certain known classes of risk, but they do not guarantee that the SustaTrace website, SustaTrace SaaS application, or any integrated component is free from vulnerabilities, defects, security weaknesses, or operational incidents.
Security properties may also depend on third-party services, infrastructure, dependencies, integrations, customer configurations, and other components outside the direct control of Mersolution.
Nothing on this page constitutes a security certification, audit opinion, guarantee, or warranty of security.
See the Legal Notice, Terms of Use, and Privacy Policy for additional terms and limitations.