### Coordinated Vulnerability Disclosure (CVD) Policy
At WireFlow AB, the security of our users, systems, and services is our top priority. We welcome and value reports from security researchers and the public to help us identify and fix potential vulnerabilities.
This policy outlines how to report vulnerabilities to us, what you can expect from our team, and the rules you must follow to be covered under our Safe Harbor protection.
### 1. Scope
**This policy applies to:**
* All products, services, and websites owned or operated by WireFlow, including:
* *.wireflow.se
* *.wireflow.com
**This policy does NOT apply to:**
* Third-party services, integrations, or platforms that we use but do not control.
* Vulnerabilities discovered via Denial of Service (DoS/DDoS) attacks, phishing, or social engineering targeting our employees, partners, or customers.
* Physical security attacks against our offices or data centers.
### 2. How to Report a Vulnerability
If you believe you have found a security vulnerability, please report it to us as soon as possible.
* **Email:** security@wireflow.com
* **Encryption:** We encourage you to use our PGP key to protect sensitive data in your report: https://wireflow.com/.well-known/wireflow-publicPGP.asc
* **Alternative Channel:** Please check our https://wireflow.com/.well-known/security.txt file for our latest contact details.
**Please include the following information in your report:**
* A detailed description of the vulnerability.
* Step-by-step instructions to reproduce the issue (Proof of Concept, PoC).
* The specific systems, URLs, or products affected.
* Any suggestions for remediation or mitigation.
### 3. Rules of Engagement
To protect our users and systems, we expect you to follow these rules during your research:
* **No Data Breach:** Do not attempt to access, modify, delete, or download data belonging to our customers or users. If you accidentally access personal or sensitive data, stop immediately and delete the data after reporting the issue to us.
* **No Disruption:** Do not perform testing that could degrade the performance or availability of our services (e.g., high-intensity automated scanning).
* **Confidentiality:** Do not share information about the vulnerability with third parties or publish it online until we have had a reasonable amount of time to patch the issue (Coordinated Disclosure).
### 4. Our Commitment and Timeline
When you submit a report, we commit to acting quickly and professionally:
1. **Acknowledgment:** We will acknowledge receipt of your report within 3 business days.
2. **Validation:** We will investigate the issue and provide a first response regarding its validity within 10 business days.
3. **Remediation:** We will work to develop and deploy a security fix. We will keep you updated during this process.
4. **Recognition:** With your permission, we will gladly give you public credit (e.g., on a "Hall of Fame" page) once the issue is resolved. *Note: We currently do not offer monetary rewards*
### 5. Safe Harbor
If you act in good faith and comply with the rules of this policy while conducting your security research, WireFlow AB will not initiate legal action or law enforcement reports against you. We consider your research to be authorized and lawful as long as you remain within the boundaries of this policy.
*This policy was last updated on: 2026-09-11