DraftPending attorney review — not final and not legal advice.
Security
How to report a vulnerability, our coordinated disclosure process, and the machine-readable security.txt.
Status: DRAFT, drafted by an LLM and not yet reviewed by an attorney. Nothing on this page is final and nothing on this page is legal advice. See the banner above.
1. Reporting a vulnerability
If you believe you've found a security vulnerability in Wirefold — the API, the web app, or the infrastructure behind either — please tell us before telling anyone else.
- Contact: security@wirefold.ai (placeholder — DNS/SES verification for this address is scheduled for a later milestone; treat as not-yet-live until then).
- A machine-readable version of this contact lives at
/.well-known/security.txtper RFC 9116.
Please include: what you found, the steps to reproduce it, and its potential impact. Proof-of-concept code is welcome; please avoid accessing, modifying, or exfiltrating other users' data beyond what's needed to demonstrate the issue.
2. Coordinated disclosure (DRAFT)
We ask that you give us a reasonable window to investigate and fix a reported issue before disclosing it publicly. In return, we intend to:
- Acknowledge your report within a reasonable timeframe (exact SLA — DRAFT, not yet set pending attorney review).
- Keep you updated as we work on a fix.
- Credit you (if you'd like) once the issue is resolved.
3. Scope (DRAFT)
In scope: the Wirefold API (api.wirefold.ai), the web app (wirefold.ai), and
infrastructure Wirefold directly controls. Out of scope: third-party services we
depend on but don't control, and issues that require physical access to a user's
device. Full scope details — DRAFT, to be expanded before this policy is finalized.
4. Safe harbor (DRAFT)
We will not pursue legal action against good-faith security research conducted under this policy — DRAFT language, pending attorney review before this is treated as a binding commitment.
5. What Wirefold does on its own side
- Outbound wires and schema payloads pass through an egress/secret-scan before delivery — see the Acceptable Use Policy for what that means for you as a user, and the Terms for the doctrine it sits under.
- No bug bounty program exists yet in V1 — this is a coordinated-disclosure-only policy for now.
6. Contact
security@wirefold.ai (placeholder). See also
/.well-known/security.txt.