# WiBiz Vulnerability Disclosure Policy

**Version:** v1.0  
**Published:** 6 August 2026  
**Owner:** WiBiz Operations  
**Classification:** Public  
**Status:** Current public policy

## 1. Purpose

Digital Benefits Pte Ltd, trading as WiBiz, welcomes good-faith reports that help protect WiBiz, our clients, and service users. This policy defines the reporting route and the testing boundaries that protect people and production services.

## 2. Reporting route

Email security@wibiz.ai with:

- the affected domain, page, application, interface, or asset;
- a clear description and potential impact;
- safe reproduction steps;
- test-account details that do not include a password;
- the time and time zone of relevant activity;
- the minimum evidence needed to validate the issue;
- your preferred contact and coordinated-disclosure request.

Do not include unnecessary personal data, client data, credentials, secrets, or confidential content.

## 3. In-scope testing

Testing may cover public WiBiz domains and applications that WiBiz owns or operates. A third-party service is in scope only when both the provider and WiBiz have given written authorisation.

Use your own accounts and test data unless WiBiz provides written permission. Use the minimum interaction needed to demonstrate the issue.

## 4. Stop conditions

Stop and report immediately if you encounter:

- personal data, client data, credentials, secrets, or confidential records;
- access beyond the minimum proof;
- a risk of service disruption, data loss, or unsafe behaviour;
- evidence that another person or organisation may be under active attack.

## 5. Prohibited activity

Do not perform:

- denial-of-service, destructive, high-volume, or availability-impacting testing;
- social engineering, phishing, physical access attempts, or targeting staff and clients;
- access, change, download, retention, or disclosure of data that is not yours;
- malware, persistence, credential stuffing, password spraying, or monitoring disruption;
- testing of a third-party service without written authority;
- public disclosure before coordinated disclosure is agreed.

## 6. Good-faith handling

If you follow this policy, act in good faith, avoid harm, and comply with applicable law, WiBiz will treat the report as authorised security research for our handling process. This does not authorise activity on a system owned by another party and does not waive any third party's rights.

## 7. Response and disclosure

WiBiz records, triages, validates, assigns, remediates, and retests accepted findings. Update timing depends on severity, scope, evidence, and third-party dependencies. Allow reasonable time for remediation before disclosure.

WiBiz does not operate a public bounty programme unless a separate written offer says otherwise.

## 8. Contact

Security reports: security@wibiz.ai

---

WiBiz Vulnerability Disclosure Policy v1.0, 6 August 2026.
