Responsible disclosure (how to report a vulnerability)
If you believe you have found a security vulnerability in Watchfox, please report it to:
We appreciate responsible disclosure. Please do not publicly disclose the issue before we have confirmed and addressed it.
What to include
To help us reproduce and fix the issue quickly, include:
- A clear description of the vulnerability and expected impact.
- Steps to reproduce (proof-of-concept is welcome).
- Affected URL(s), endpoint(s), and account/role assumptions.
- If available: timestamps and any relevant IDs shown by the app, for example
request_idortrace_id. - Your preferred contact for follow-up and whether you want public credit.
Safe harbor (good-faith testing)
We consider research to be in good faith if you:
- Only test against accounts and data you own or have explicit permission to use.
- Do not intentionally access or modify other customers’ data.
- Do not perform disruptive testing, for example DoS, spam, or brute force.
- Do not use social engineering, phishing, or physical attempts.
If you are unsure whether a test is acceptable, email us first at [email protected].
Scope
This policy applies to Watchfox services and properties, including:
app.watchfox.iowatchfox.io*.watchfox.io— Watchfox-operated subdomains only.
Our response targets
- Acknowledgement: within 24 hours.
- Triage: we will validate and assess severity as soon as possible.
- Fix: we prioritize issues by severity and exploitability.
- Disclosure: we will coordinate timing with you. We may publish a short note after a fix ships.
High-level vulnerability handling process
When a vulnerability report is received at [email protected], Watchfox will:
1. acknowledge receipt, normally within 24 hours; 2. create a private internal security issue; 3. restrict access to the smallest necessary group; 4. reproduce and assess severity where possible; 5. mitigate or fix the issue using the lowest-risk effective change; 6. coordinate disclosure timing with the reporter when appropriate.
Security reports must not be posted into public channels, broad shared workspaces, public issue trackers, or customer-visible status updates unless a public notice is intentionally prepared after mitigation.
Note: We do not currently run a paid bug bounty program, but we are happy to credit reporters for valid findings upon request.