Meridian Civic Systems
Vulnerability disclosure Managed triageMeridian Civic Systems Authority
Shared permitting, transit fares and open data for the nineteen municipalities that own us.
- Accepting reports
- No cash reward
- 8 assets in scope
- Launched Aug 2019
- meridiancivic.example
Read the policy · first response 2 business days
Response times
- first response
- 9 hours
- triage
- 3 business days
- reward
- No payment at any severity
- resolution
- 38 days
Program to date
- Resolved
- 1,742
- Thanked
- 397
Rewards by severity
This program does not pay cash. Severity still drives priority, credit and disclosure timing.
| Severity | CVSS | Reward | Typical findings |
|---|---|---|---|
| Critical | 9.0 – 10.0 | Recognition only | Nothing is paid at this or any tier. A Critical finding earns a signed letter from the executive director naming the issue and its impact, a line in the annual security report the councils read in open session, and a permanent entry on the credits page. |
| High | 7.0 – 8.9 | Recognition only | No payment. A letter on Authority letterhead, an entry on the credits page, and named credit inside the remediation notice that circulates to every member clerk. |
| Medium | 4.0 – 6.9 | Recognition only | No payment. An entry on the credits page and a written account of what we changed, which is the part most reporters say they actually wanted. |
| Low | 0.1 – 3.9 | Recognition only | No payment. Credit by the handle you choose, and written confirmation that the issue was reviewed, closed, and by whom. |
In scope
8 assets listed. Anything not on this list is out of scope.
| Asset | Type | Max severity | Reward | Notes |
|---|---|---|---|---|
| permits.meridiancivic.example | URL | Critical | No reward | Building, zoning and licensing portal for all nineteen members. Holds applicant records, so stop at proof rather than at completeness. |
| id.meridiancivic.example | Domain | Critical | No reward | Resident and staff identity service, rebuilt in 2020. Session handling, recovery flows and the staff role model are the priority. |
| api.meridiancivic.example | API | Critical | No reward | Shared service layer behind every portal here. Authorisation boundaries between one municipality and the next matter more than anything else. |
| fares.meridiancivic.example | URL | High | No reward | Transit fare accounts and pass purchase. Card numbers are tokenised at the processor and never reach us. Keep below 10 requests per second. |
| inspections.meridiancivic.example | URL | High | No reward | Field inspector workflow. Staff-facing, and it holds photographic evidence attached to open code enforcement cases. |
| notify.meridiancivic.example | API | High | No reward | Resident notification service added in June 2026. It can send messages to real people, so test only against recipients you registered. |
| data.meridiancivic.example | URL | Medium | No reward | Open data platform. The published datasets are public on purpose; the publishing workflow behind them is not. |
| legacy.meridiancivic.example | URL | Low | No reward | Read-only archive of the permit system retired in 2022. Capped at Low, decommissioned in the first quarter of 2027, and only authentication defects will be fixed before then. |
Out of scope
| Asset | Why |
|---|---|
| Any election system operated by a member county board of elections | Prohibited without exception. The Authority does not run these systems, cannot authorise testing of them, and will refer observed activity to the responsible board. |
| Emergency call handling, computer-aided dispatch, and responder paging | Prohibited without exception. Interference risks a delayed response to a real emergency. There is no circumstance in which we authorise it. |
| pay.meridiancivic.example | Operated end to end by a contracted payment processor under that vendor's own published disclosure policy. |
| Member municipality websites not hosted under meridiancivic.example | Separate governments with their own authority to give. We will forward a report if you ask us to, and we cannot authorise the testing. |
| Fare gates, ticket machines and permit kiosks | Physical equipment standing in public space. Hardware and physical testing are excluded in every circumstance. |
| Court, jail and prosecutor case management systems | Operated by the judicial branch of each county, which is outside the Authority's charter entirely. |
| Staff email, payroll, and the internal document management system | Corporate systems with no resident-facing surface, covered by a separate internal assessment programme. |
Findings that will be closed as informative
- Automated scan output with no reproduction a reviewer can follow step by step.
- Missing headers, cookie attributes or cipher preferences with no impact shown.
- Disclosure of information already published on the open data platform or routinely released under public records law.
- Self-XSS, clickjacking with no state change behind it, and reverse tabnabbing.
- Load generation, or any test that could delay a permit decision or a fare transaction.
- Social engineering of municipal employees, contractors, call centre staff or front-counter clerks.
- Physical access attempts at any Authority or member facility, including tailgating and badge cloning.
- Findings in third-party software already covered by a vendor advisory and scheduled in our patch window.
- Requests for payment, since no council has appropriated a dollar for one and we cannot invent it.
Program policy
Program overview
Meridian Civic Systems Authority is a joint agency chartered in 2019 and owned by the nineteen municipalities it serves. We run the software those members share: permitting and licensing, transit fare accounts, field inspections, open data, and the identity service they all sit on.
This is a vulnerability disclosure policy. It does not pay. There is no bounty appropriation, and creating one would take a budget action carried in nineteen council chambers. What we offer instead is a triage team that answers within a working day, a written account of what we changed, credit under the name you choose, and for serious findings a signed letter from the executive director. Reporters tell us the letter is the part they wanted.
Testing rules and expectations
Register your own accounts. File practice applications against the training parcel at permits.meridiancivic.example/training, prefix every free-text field with VDP-TEST, and never file against a real address or into a queue a clerk has to empty.
Stay under ten requests per second and stop as soon as a finding is proved. If you reach records belonging to a resident, an applicant or an employee, capture the minimum that shows the exposure and stop. Do not enumerate, and do not attach the records: describe them and we will pull them ourselves.
Systems you may never test
Two categories sit outside this policy and outside every protection in it.
Election systems. Voter registration, ballot preparation, tabulation, results reporting, and any system supporting them at a member county board of elections. The Authority neither runs them nor holds the standing to authorise testing.
Emergency dispatch. Emergency call handling, computer-aided dispatch, responder paging, and the interfaces between them. Interference risks a delayed response to a real emergency, and the risk is not ours to accept on a resident's behalf.
Neither is a scope violation to be argued afterwards: testing either is unauthorised access, and this page will not help you.
Proving write access
If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.
- One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
- Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
- Revert within sixty seconds, in the same run, without being asked.
- Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
- If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.
Every request must carry headers that let us separate your traffic from a real attack in our logs:
X-Bug-Bounty: meridian-civic
X-Research-Account: <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id: <unique per request>
User-Agent: sentinel-research/<handle> (+<this page>)
scripts/proof_of_write.py performs exactly this sequence, refuses any host
outside the scope above, refuses a diff longer than two characters, always
attempts the revert, and writes a timestamped evidence file. Run it without
--execute first, then attach the evidence to your report.
Safe harbor
Read this before you start; it is the section we have revised most.
Authorisation
The Authority authorises good-faith security research conducted under this policy against the assets listed in scope. It gives that authorisation on its own behalf and on behalf of each of its nineteen member municipalities, whose counsel approved this wording in August 2026.
Research inside this policy is authorised access. It is not unauthorised access, it does not exceed authorised access, and it does not breach the terms of service of the systems above. Where an Authority contract or acceptable use policy would otherwise forbid it, this policy governs for the duration of your research.
No reporter who stays inside this policy will face civil or criminal proceedings brought or supported by the Authority, and we will not ask any prosecutor to open one. If a third party begins an action arising from authorised research, we will confirm the authorisation in writing, on letterhead, to that party and to any court that asks.
Acting in good faith
You are in good faith when you work only on in-scope assets, use accounts you registered, stop at proof instead of collecting, leave public services running on time, and come to us before you go anywhere else.
If an agency contacts you
Municipal networks are monitored and alerts reach investigators. In July 2025 a reporter was questioned by a member police department over testing this policy expressly permitted, which is why this paragraph exists.
Contact us immediately. Tell us who approached you and what they asked, and send the hours you were testing so we can line them up against our logs. You may state that you are conducting authorised research under this policy and refer the officer or the agency to us. We confirm your authorisation in writing to them within one business day, and have done so four times. Keep your notes, logs and captures. Do not withdraw your submission.
What ends this authorisation
Testing a prohibited system. Retaining resident, applicant or employee records beyond minimum proof. Altering or deleting a government record. Disrupting a public service. Using a finding for personal gain. Asking for money in exchange for silence. Publishing before the coordinated window closes. Where authorisation ends, we say so in writing and name the conduct that ended it.
Public records
Your submission is a record held by a public agency and may be subject to disclosure under public records law. We assert the exemptions available for security information and for a reporter's identifying details, and have prevailed each time. We will notify you before any release we are compelled to make. We cannot promise confidentiality that is not ours to give, so if anonymity matters to you, submit under a pseudonym and tell us nothing that identifies you.
Reward decisions
With no money to allocate, what gets decided is severity, and severity sets priority. We start at CVSS v3.1 and adjust for civic consequence: a resident's home address beside their permit history is treated more seriously than the base score suggests, as is anything that could delay an occupancy certificate or hold a rider at a fare gate. Duplicates are settled by receipt timestamp, and both reporters are credited.
Disclosure policy
Coordinated, ninety days from acknowledgement, with one extension of thirty days where a fix depends on a vendor release or a council-approved change window. We tell you which of the two applies and name the date.
After the window, publish. Redact personal information, internal hostnames, parcel identifiers and case numbers. Send the draft five business days ahead; we read it for redaction only.
Report quality
- The asset, URL, method and parameter written out, not described in prose.
- Numbered steps from account registration, followable by a reviewer new to the system.
- The handles and
VDP-TESTmarkers you used, so we can find and remove your test data. - Impact in civic terms: which residents, which municipality, which service.
- The date, the time window and the source address you tested from.
- Whether you want to be named or anonymous, and the exact spelling to use.
Hall of fame
Researchers who have reported valid issues to this program.
| # | Researcher | Country | Reports | Points |
|---|---|---|---|---|
| 1 | parcelfold | United States | 58 | 6,420 |
| 2 | clerk_of_records | Canada | 47 | 5,610 |
| 3 | faregate_lin | Singapore | 33 | 4,930 |
| 4 | zoning_variance | United Kingdom | 41 | 4,375 |
| 5 | opendata_owl | Nigeria | 36 | 3,820 |
| 6 | permitqueue | Australia | 28 | 3,240 |
| 7 | hydrant_hex | Mexico | 24 | 2,755 |
| 8 | sunshine_req | Ireland | 15 | 2,180 |
| 9 | plat_map | India | 21 | 1,845 |
| 10 | counterclerk | Philippines | 17 | 1,490 |
| 11 | busstop_null | Poland | 13 | 1,115 |
| 12 | ordinance_ada | Türkiye | 11 | 860 |
| 13 | taxroll_ty | Kenya | 8 | 545 |
| 14 | curbcut | Ukraine | 5 | 320 |
Program updates
-
Authorisation language re-approved by every member
The safe harbor section was re-read and signed off by the legal department of all nineteen municipalities. A researcher now has one set of protections rather than nineteen slightly different ones.
-
Resident notification service entered scope
The service that sends permit and fare alerts is now testable at High severity. It can reach real residents, so only recipients you registered yourself are fair game.
-
Membership reached nineteen
Two more councils joined in January and their permit data finished migrating in March. Every new member inherits this policy on the day they join.
-
Guidance added for researchers contacted by an agency
A reporter working inside this policy was questioned by a municipal police department after an intrusion alert fired. We confirmed the authorisation in writing the same afternoon, and the safe harbor section now says exactly what to do when it happens again.
-
Patch window moved to the second Tuesday
An Authority-wide change window removed most of the scheduling delay between a triaged report and a deployed fix. Median resolution fell from 71 days to 38.
-
Inspections workflow added to scope
The field inspector application entered scope at High severity, along with the photographic evidence it stores against open enforcement cases.
-
Public records caveat written into the policy
A request under public records law sought the text of a submission. We asserted the security exemption and prevailed, then wrote the caveat on this page so nobody is surprised by the next one.
-
Four municipalities joined and fares consolidated
Four members moved onto the shared fare platform over the summer, which doubled the size of the fares surface and added two triagers to the team.
-
The old permit system went read-only
Applications from before 2022 now live in an archive at legacy.meridiancivic.example. It stays in scope at Low severity until it is switched off in 2027.
-
Prohibited systems restated after a question in good faith
A researcher asked, reasonably, whether dispatch infrastructure was testable. It is not, and the prohibition now appears in three separate places on this page.
-
Identity service rebuilt after the first Critical
A session fixation finding in the original single sign-on implementation led to a full rebuild rather than a patch. The reporter reviewed the replacement before it shipped.
-
Policy published with eight founding municipalities
The Authority opened this programme four months after it was chartered, with eight members and one part-time triager. Both numbers have grown since.