Maree-DB is built on the principle that security must be correct, not just convenient. We take all security reports seriously.
Report a Vulnerability →Maree-DB is engineered to meet the requirements of FIPS 140-3 (the cryptographic module self-runs NIST Known Answer Tests on every boot and refuses to start if any test fails), Common Criteria EAL4+ (a security target is maintained alongside the codebase), SOC 2 and ISO 27001:2022 (the engine generates its own audit evidence with a single SQL query).
Maree-DB has not yet completed a formal third-party certification, and we will never imply otherwise - certification labels belong to auditors, not vendors. Formal validation programmes (FIPS 140-3 validation, Common Criteria evaluation, SOC 2 attestation) are undertaken with enterprise customers as their procurement requires, and validation artefacts - Known Answer Test reports, the security target, and evidence exports - are available to customers under NDA.
You can execute the entire control suite yourself, on your own hardware, in one run: maree-db-server certify (or SELECT * FROM CERTIFY()) executes a real test for every certification-relevant control - cryptographic Known Answer Tests, post-quantum round-trips, tamper-detection, audit-evidence generation, access-control gating - and emits a tamper-evident attestation report with exit code 0 only when every control passes.
We operate a responsible disclosure programme for security vulnerabilities in Maree-DB software and the mareedb.com website. If you discover a security vulnerability, we ask that you report it privately to us before public disclosure, giving us reasonable time to address it.
We will acknowledge receipt of your report and confirm we have received all necessary details.
We will assess the severity, confirm the vulnerability, and assign it to an engineer. You will receive an initial assessment of severity and likely resolution timeframe.
Critical vulnerabilities (CVSS 9.0+) will have a patch developed and released within 30 days where possible.
High-severity vulnerabilities will be addressed within 90 days. We will coordinate with you on disclosure timing.
We will work with you to coordinate public disclosure after the fix is released. We will credit you in our security advisory (unless you prefer to remain anonymous).
We will not pursue legal action against security researchers who:
We consider good-faith security research a public service. We will treat your report with respect and handle it professionally.
In scope:
Out of scope:
We recognise security researchers who responsibly disclose vulnerabilities to us. The following researchers have helped make Maree-DB more secure.
We do not currently operate a formal paid bug bounty programme. We do, however, offer recognition in our Hall of Fame, a thank-you in our release notes, and may offer a complimentary licence as a token of appreciation for significant findings - at our discretion.