WiBizTrust Center

WiBiz Secure Change and Vulnerability Management Summary

Version: v1.0
Published: 6 August 2026
Owner: WiBiz Operations
Classification: Public
Status: Current public summary

1. Purpose

This summary describes how WiBiz records security requirements, controls production change, tests releases, receives vulnerability reports, remediates findings, and requires closure evidence.

2. Secure delivery commitments

Applicable builds require:

  • defined security, privacy, data, and client acceptance criteria;
  • architecture and data-flow review before production approval;
  • threat and abuse-case assessment for material functions;
  • version control, peer review, release ownership, and rollback planning;
  • separation of production and non-production data and access where applicable;
  • dependency, secret, application, authorization, configuration, and recovery checks appropriate to the assurance tier;
  • immutable release and evidence references;
  • independent review where the build risk or contract requires it.

3. Vulnerability lifecycle

Reported or detected vulnerabilities are recorded with the affected asset, environment, version, severity, business impact, owner, deadline, evidence, exception, remediation, retest, and closure status.

Critical and High findings block production unless an accountable approver accepts a time-limited exception with a documented compensating control and client approval where the commitment affects the client.

4. Independent testing

Independent testing is scoped to named domains, applications, interfaces, roles, environments, dates, and versions under written authorisation and Rules of Engagement. The detailed report remains restricted. A client-shareable executive summary and retest closure letter may be provided through an approved confidential route.

A penetration test is point-in-time evidence. It does not validate every programme control and must be refreshed after material change, serious incident, or expiry.

5. Reporting

Read the Vulnerability Disclosure Policy before testing. Reports may be sent to security@wibiz.ai.


WiBiz Secure Change and Vulnerability Management Summary v1.0, 6 August 2026.