Security at Wolfia
This page describes how to report a security issue to Wolfia and what to expect when you do.
Reporting a vulnerability
If you believe you have found a security issue in Wolfia, email security@wolfia.com with “[SECURITY]” in the subject line. Include the affected URL or endpoint, steps to reproduce, and the account you used. Send one issue per email.
Please report privately and allow us 90 days to respond before any public disclosure.
Scope
Our vulnerability disclosure program covers the Wolfia application at wolfia.com, tested only through accounts and data you created yourself. All customer data, customer trust centers, third-party services we integrate with, and any host not listed here are out of scope.
Testing outside this scope, or testing that has not been agreed with us in writing beforehand, is not authorized.
Rules of engagement
Safe harbor applies to research that follows these rules: it is authorized, and we will not pursue legal action for it.
- Use only accounts, organizations, and data you created yourself. Never access or modify another customer’s data; if you reach it by accident, stop and report immediately.
- No automated scanning, high-volume requests, or anything that could degrade availability.
- No social engineering of Wolfia staff or customers.
- Stop at proof of concept. Do not go further than is needed to demonstrate the issue once.
What to expect
This is a responsible disclosure program without bounties. We do not offer monetary rewards for security reports. Out-of-scope reports may be reviewed at our discretion and are not eligible for acknowledgement.
We acknowledge in-scope reports within five business days, and confirmed findings are fixed on a timeline set by severity. Automated tool output without a demonstrated impact is closed without response.