Skip to content

Security

Report a vulnerability

Send suspected vulnerabilities in Witen products or services to security@witenlabs.com. We acknowledge reports within two business days and aim to complete initial triage within five business days.

What to include

Describe the affected product and version, the expected and observed behavior, impact, and the smallest safe reproduction you can provide. Tell us your preferred name or alias for acknowledgement and any disclosure timeline you need us to consider. Do not send credentials, personal data, or destructive proof.

How we handle reports

We assign an owner, validate only in authorized environments, coordinate with affected vendors when necessary, and preserve corrections, disputes, and withdrawals in the advisory history. We do not promise a bounty. We will agree on disclosure timing before publishing embargoed material.

Research boundaries

Avoid privacy violations, service disruption, social engineering, persistence, data destruction, and testing systems you do not own or lack permission to test. Stop after demonstrating the issue with the least impact needed. This page does not authorize access to any system.