Security
Report a vulnerability
Send suspected vulnerabilities in Witen products or services to security@witenlabs.com. We acknowledge reports within two business days and aim to complete initial triage within five business days.
What to include
Describe the affected product and version, the expected and observed behavior, impact, and the smallest safe reproduction you can provide. Tell us your preferred name or alias for acknowledgement and any disclosure timeline you need us to consider. Do not send credentials, personal data, or destructive proof.
How we handle reports
We assign an owner, validate only in authorized environments, coordinate with affected vendors when necessary, and preserve corrections, disputes, and withdrawals in the advisory history. We do not promise a bounty. We will agree on disclosure timing before publishing embargoed material.
Research boundaries
Avoid privacy violations, service disruption, social engineering, persistence, data destruction, and testing systems you do not own or lack permission to test. Stop after demonstrating the issue with the least impact needed. This page does not authorize access to any system.