Watchfox

Legal & trust

Watchfox Security

Security contact, responsible disclosure, and high-level vulnerability handling process.

Last updated: 2026-04-25

Responsible disclosure (how to report a vulnerability)

If you believe you have found a security vulnerability in Watchfox, please report it to:

[email protected]

We appreciate responsible disclosure. Please do not publicly disclose the issue before we have confirmed and addressed it.

What to include

To help us reproduce and fix the issue quickly, include:

Safe harbor (good-faith testing)

We consider research to be in good faith if you:

If you are unsure whether a test is acceptable, email us first at [email protected].

Scope

This policy applies to Watchfox services and properties, including:

Our response targets

High-level vulnerability handling process

When a vulnerability report is received at [email protected], Watchfox will:

1. acknowledge receipt, normally within 24 hours; 2. create a private internal security issue; 3. restrict access to the smallest necessary group; 4. reproduce and assess severity where possible; 5. mitigate or fix the issue using the lowest-risk effective change; 6. coordinate disclosure timing with the reporter when appropriate.

Security reports must not be posted into public channels, broad shared workspaces, public issue trackers, or customer-visible status updates unless a public notice is intentionally prepared after mitigation.

Note: We do not currently run a paid bug bounty program, but we are happy to credit reporters for valid findings upon request.

Use the right mailbox so we can route your request quickly.