Draft template - this document must be reviewed and completed by a qualified legal professional before Webforta is offered to customers. Bracketed text marks information that still has to be confirmed.

Responsible Disclosure Policy

How to report a security vulnerability in Webforta.

Reporting

Email security@webforta.com with a description, reproduction steps and impact. Please do not include sensitive personal data. We aim to acknowledge reports within 5 business days. [Confirm response targets you can meet.]

Guidelines

  • Only test against your own account and data.
  • Do not degrade the service, access other customers’ data, or use social engineering or physical attacks.
  • Give us reasonable time to fix the issue before public disclosure.

Safe harbor

We will not pursue legal action against good-faith research that follows this policy. [Have counsel review safe-harbor wording.] We do not currently operate a paid bug bounty.


Other policies: Terms of Service · Privacy Policy · Cookie Policy · Acceptable Use Policy · Security Testing Authorization Terms · Data Retention and Deletion Policy · Responsible Disclosure Policy ·