Skip to content

Winglark

Trust & Security Center

Report a vulnerability.

We welcome reports from researchers and customers who find a weakness in Winglark. Please tell us privately first, so we can fix it before anyone else can use it.

What to include

  • What you found and where (the page or address involved).
  • The steps to reproduce it, and what an attacker could achieve.
  • Any accounts or test data you used.
  • How we can reach you for follow-up questions.

How to test responsibly

  • Test only with accounts and data you own or have permission to use.
  • Do not access, change or delete other people’s data; stop as soon as you reach data that is not yours.
  • Do not degrade the service: no denial-of-service, load or spam testing.
  • Do not use social engineering or physical attacks against our team or customers.
  • Give us reasonable time to fix the issue before sharing it publicly.

Usually not in scope

  • Reports produced only by automated scanners, without a demonstrated impact.
  • Missing best-practice headers or settings without a practical attack.
  • Issues in third-party services that we do not control.

After you report

Every report is read by the people who build Winglark. We will confirm that we have it, investigate, and keep you informed while we work on a fix.

Back to the Trust & Security Center

Responsible disclosure · Winglark