Our promise
If you follow this policy when reporting a vulnerability to us, we will:
- Acknowledge your report within 72 hours, business or not.
- Triage and give you an initial assessment within 5 business days.
- Keep you informed of our progress at least every 14 days until the issue is fixed.
- Credit you in our Hall of Fame if you ask (and as long as your report complies).
- Treat your report as confidential. We will not share your name or report outside the team that needs to know.
- Not pursue legal action against you for the act of reporting, when you have followed this policy.
This policy is aligned with ISO/IEC 29147 and ISO/IEC 30111, the disclose.io core terms, and the EU Cyber Resilience Act disclosure expectations.
In & out of scope
- getwaved.ai and all subdomains in production.
- The Wavelink profile pages served from our domain.
- Our Cloudflare Pages Functions (the API powering forms, geo lookup, lead capture).
- The Cloudflare Worker that handles asset routing.
- Our mobile-web experience (no native app is in production).
- Third-party platforms we link to (WhatsApp, Facebook, Instagram, YouTube, TikTok, X).
- Cloudflare's own platform — report those to Cloudflare.
- Microsoft Clarity analytics — report to Microsoft.
- Denial-of-service, rate-limiting bypasses against non-PII endpoints.
- Self-XSS, missing security headers on third-party assets.
- Issues that require a rooted device, jailbroken phone, or compromised network.
How to report
Send a clear, reproducible report. The format below lets us act fastest.
Report template
- Title — Title — one line, what is the issue.
- Asset — Asset — URL or component affected.
- Severity — Severity — your estimate (Critical / High / Medium / Low).
- Description — Description — what is the issue and what is the impact.
- Steps to reproduce — Steps to reproduce — exact steps we can follow.
- Proof of concept — Proof of concept — screenshot, video, or command output.
- Suggested fix — Suggested fix — optional but very welcome.
- Your handle — Your handle — for Hall of Fame credit, if you want it.
Where to send
- Email: security@getwaved.ai
- PGP fingerprint: 2B7E 5F19 8C4A 1D83 (rotates quarterly)
- Signal: request from security@getwaved.ai
Reports are read by a member of our engineering team. We never outsource triage.
Safe harbor
When you conduct research and submit a report under this policy, we consider the research to be:
- Authorised under our Terms of Service — we will not bring a claim against you for the act of reporting.
- Exempt from the UAE Federal Decree-Law No. 34 of 2021 restrictions on unauthorised access, provided your testing was strictly necessary to demonstrate the vulnerability and you caused no harm beyond what the demonstration required.
- Aligned with "good faith" research exceptions in EU, UK, US (CFAA), and Singapore cybersecurity laws.
If your research inadvertently accesses personal data
stop, do not download, and tell us. We will work with you to delete or quarantine any data created by your activity.
This safe harbor extends only to research that complies with this policy. It does not cover unrelated criminal activity, extortion, or publication of a vulnerability before we have had a reasonable time to fix it.
Severity & response times
We classify by impact, using the CVSS v3.1 base score as a starting reference.
| Severity | Example | Our target |
|---|---|---|
| Critical | Account takeover, PII mass exposure | Acknowledge in 24h · Fix in 7 days |
| High | Stored XSS, authentication bypass | Acknowledge in 72h · Fix in 30 days |
| Medium | Reflected XSS, missing rate limit | Acknowledge in 5 days · Fix in 60 days |
| Low | Information disclosure, hardening | Acknowledge in 7 days · Fix in next release |
"Fix" means deployed to production. We notify you when the fix ships.
Hall of fame
Researchers who report a valid, previously-unknown vulnerability may be added to our Hall of Fame if they wish. We never publish reports without consent.
The Hall of Fame is opened to entries from the first quarter of 2027, once we have processed enough reports to make it meaningful. Researchers whose reports predate that are added retroactively on request.
Out of bounds
The following activities are not authorised under this policy and may remove safe harbor:
- Public disclosure of a vulnerability before we have confirmed a fix.
- Accessing, downloading, or modifying data beyond what is strictly necessary to demonstrate the issue.
- Using a vulnerability to demand payment, ransom, or any form of consideration.
- Testing on production systems in a way that degrades service for other customers.
- Social engineering or phishing of our staff.
- Physical attacks against our offices, hardware, or staff.
This policy is referenced from /.well-known/security.txt as our disclosure policy under RFC 9116.