SECURITY & VULNERABILITY DISCLOSURE POLICY

REPORT RESPONSIBLY.

How good-faith security researchers can responsibly test and report issues in WAE-owned public web assets — what is in scope, what is prohibited, what to include in a report, and what happens next. No invented SLAs, no invented bounties.

PURPOSE

WAE Media, LLC welcomes good-faith reports of security issues in its own public web assets. This policy explains how to test and report responsibly, what WAE considers in scope, and what behavior is prohibited. Following this policy does not create any contract, employment, or service relationship between you and WAE.

SCOPE

In-scope assets are WAE-owned public web surfaces on waehq.com — the public website athttps://waehq.com, its public pages, and its public static assets. Testing must be non-destructive and limited to these surfaces.

Out of scope, unless separately and explicitly authorized in writing by WAE Media, LLC:

  • any internal, private, administrative, or authentication-gated WAE system;
  • any other WAE domain, brand site, or subdomain;
  • systems operated by third parties, including Cloudflare, Meta, GitHub, Google, or any infrastructure provider WAE uses — using a third-party service is not authorization to test that third party; and
  • the APIs, platforms, or properties of Meta (Facebook, Instagram) or any other platform WAE connects to.

If you find a vulnerability in a third-party system while testing an in-scope asset, stop testing that system and report the observation to WAE; WAE will route it appropriately if possible.

GOOD-FAITH RESEARCH AND AUTHORIZATION

WAE welcomes responsible, good-faith vulnerability reports about its own in-scope public web assets and appreciates researchers who test non-destructively and report promptly. This policy describes how WAE would like research and reporting to be conducted.

This policy is a responsible-disclosure boundary, not a grant of immunity: it does not promise legal safe harbor, does not promise that WAE will not take legal action, and does not waive any of WAE's rights. It does not authorize any activity beyond non-destructive testing of the in-scope WAE-owned public assets described above, and it never authorizes activity on third-party systems or activity that violates applicable law.

Researchers who stay within this boundary make WAE's review and coordination materially easier, and WAE asks reporters to follow the coordinated-disclosure expectations below.

ALLOWED RESEARCH

Reasonable, non-destructive testing of in-scope public web surfaces, for example:

  • reviewing public page content, markup, headers, and configuration files that WAE itself publishes;
  • testing for common web vulnerabilities (such as reflected content handling or weak configuration) without exploiting access controls;
  • using your own test accounts or data only;
  • automated scanning at a low, non-disruptive rate; and
  • reporting your findings in accordance with this policy.

PROHIBITED AND HIGH-RISK ACTIVITIES

The following are prohibited in connection with any research or reporting activity, whether in scope or not:

  • denial-of-service, distributed denial-of-service, resource exhaustion, or any testing that degrades or disrupts service;
  • destructive testing, or modifying, deleting, or corrupting data;
  • social engineering, phishing, pretexting, or manipulating WAE personnel, users, or vendors;
  • credential stuffing, password guessing or cracking, or any attack on authentication;
  • spam, bulk messaging, or abusive traffic;
  • physical attacks or attempts to gain physical access;
  • installing persistence, backdoors, or malware of any kind;
  • accessing another person's account, data, or content beyond the minimum necessary to confirm a vulnerability, and never in bulk;
  • bulk extraction of personal data;
  • intentionally disrupting production systems, services, or users; and
  • any activity that violates applicable law or any applicable third-party terms.

If your testing would require any of the above to confirm an issue, stop and report the observation instead.

IF YOU ENCOUNTER SENSITIVE DATA

If, during research, you encounter personal information, credentials, secrets, or private content:

  • minimize your access immediately — do not explore further than needed to confirm the issue;
  • do not retain, copy, redistribute, or publish the data;
  • stop any unnecessary exploration of the data; and
  • report the issue to WAE, describing the data you encountered at a level sufficient to locate it without reproducing it.

WHAT A USEFUL REPORT CONTAINS

  • the affected asset or URL;
  • the vulnerability type and its likely impact;
  • clear, reproducible steps (minimal proof of concept only — do not attach exploit tooling);
  • relevant screenshots or log excerpts where safe to include; and
  • a contact address if you choose to provide one (optional).

Write the report in English where possible. Do not include credentials, personal data of third parties, or bulk data extracts.

COORDINATED DISCLOSURE

WAE asks researchers to give WAE a reasonable opportunity to investigate and remediate before publicly disclosing a vulnerability. WAE's goal is to acknowledge reports and work with reporters; however, WAE does not guarantee a fixed response or remediation timeline, and no SLA is promised by this policy.

If you report in good faith and later believe the issue needs public attention for safety reasons, coordinate the timing with WAE where reasonably possible.

BOUNTY STATUS

WAE does not currently operate a bug-bounty or paid vulnerability-rewards program. Submitting a report does not create any entitlement to compensation, reward, or payment of any kind. If WAE establishes a bounty program in the future, it will be announced on this page.

REPORTING CONTACT

Send security reports to:

[email protected]

Suggested subject line: Security Vulnerability Report — WAE HQ.

This is WAE's monitored institutional channel. WAE does not currently operate a dedicated security-reporting mailbox, so please use the subject line above so reports are triaged as security correspondence.

Do not send credentials, malicious attachments, or bulk data through email. If you need to share a large or sensitive proof of concept, describe it in the report first and WAE will propose a secure exchange method.

POLICY STATUS AND CHANGES

This policy is effective as of September 21, 2026 and may be updated as WAE's security practice evolves. The authorized scope, contact, and bounty status stated on this page are the current versions. Any material change will be published here and mirrored in WAE's security.txt discovery file.