WiBizTrust Center
Public policy v1.0 · 6 August 2026

Vulnerability Disclosure Policy

We welcome good-faith reports that help protect WiBiz, our clients, and service users. This policy defines a safe reporting route and the testing boundaries that protect people and production services.

Report a concern

Email security@wibiz.ai with the affected asset, description, reproduction steps, potential impact, and enough evidence for us to validate the issue without exposing unnecessary personal or confidential data.

In scope

  • Public WiBiz domains and applications that WiBiz owns or operates.
  • Authorization, authentication, tenant isolation, input handling, data exposure, and security-configuration weaknesses.
  • Third-party services only where WiBiz has expressly authorised testing in writing.

Permitted testing

  • Use the minimum interaction needed to demonstrate the issue.
  • Use your own accounts and test data unless WiBiz gives written permission.
  • Stop and report immediately if you encounter personal data, client data, credentials, secrets, or access beyond the minimum proof.
  • Allow reasonable time for validation and remediation before any disclosure.

Prohibited activity

  • Denial-of-service, destructive, high-volume, or availability-impacting testing.
  • Social engineering, phishing, physical access attempts, or targeting staff and clients.
  • Accessing, changing, downloading, retaining, or disclosing data that is not yours.
  • Persistence, malware, credential stuffing, password spraying, or disruption of monitoring.
  • Testing a third-party provider without that provider's and WiBiz's written authorisation.
  • Public disclosure before coordinated disclosure is agreed.

Good-faith handling

If you follow this policy, act in good faith, avoid harm, and comply with applicable law, WiBiz will treat the report as authorised security research for our handling process. This statement does not authorise activity on systems owned by another party and does not waive any third party's rights.

What happens next

We record, triage, validate, assign, remediate, and retest accepted findings. Update timing depends on severity, scope, third-party dependencies, and evidence. WiBiz does not operate a public bounty programme unless a separate written offer says otherwise.