Skip to content
Planet background-min

Vulnerability Disclosure Policy

LAST MODIFIED ON 20 JULY 2026

Purpose

At Whalebone, we are committed to securing our customers’ data and protecting our service infrastructure to prevent service disruptions. We appreciate the work of security researchers and believe that fostering a positive relationship with the community helps us build a more secure and reliable service. This policy outlines how to report vulnerabilities and what you can expect from us in return.

Safe Harbor

If you conduct your security research in good faith and comply with this policy, we will consider your research to be authorized. We will not initiate legal action or a law enforcement investigation against you for your activities.

Scope

This policy applies to the following assets and vulnerability types:

In-Scope Assets

  • Web applications and public APIs: *.whalebone.io

  • DNS Resolvers

  • Corporate website: www.whalebone.io

Out of Scope

  • Third-party services, such as Elasticsearch and Twilio

  • Physical security of offices or data centers

  • Social engineering or phishing of our employees

  • Denial-of-service attacks, including DoS and DDoS attacks

Guidelines

To remain in safe harbor, you must:

Notify us promptly: Report the issue as soon as it is discovered.

Avoid harm: Do not disrupt services, destroy data, or access customer information beyond what is necessary for a proof of concept (PoC).

Stop at sensitive data: If you encounter personally identifiable information (PII), stop immediately and notify us.

Maintain confidentiality: Do not disclose findings to third parties until we have remediated the issue and agreed on a disclosure timeline.

Reporting Process

Please send reports to security@whalebone.io. A valid report should include:

Summary: A brief description of the vulnerability and its potential impact.

Reproduction steps: Clear, step-by-step instructions to reproduce the issue.

Proof of concept: Screenshots, screen recordings, or scripts showing the exploit.

Target details: The URL, endpoint, or software version affected.

What to Expect

When you report a vulnerability, we commit to:

Acknowledgment: We will acknowledge receipt of your report within three business days.

Triage: We will investigate and confirm the vulnerability as quickly as possible.

Remediation: We aim to fix critical issues within 10 days.