Vulnerability Disclosure Policy
Purpose
Safe Harbor
Scope
This policy applies to the following assets and vulnerability types:
In-Scope Assets
-
Web applications and public APIs: *.whalebone.io
-
DNS Resolvers
-
Corporate website: www.whalebone.io
Out of Scope
-
Third-party services, such as Elasticsearch and Twilio
-
Physical security of offices or data centers
-
Social engineering or phishing of our employees
-
Denial-of-service attacks, including DoS and DDoS attacks
Guidelines
To remain in safe harbor, you must:
Notify us promptly: Report the issue as soon as it is discovered.
Avoid harm: Do not disrupt services, destroy data, or access customer information beyond what is necessary for a proof of concept (PoC).
Stop at sensitive data: If you encounter personally identifiable information (PII), stop immediately and notify us.
Maintain confidentiality: Do not disclose findings to third parties until we have remediated the issue and agreed on a disclosure timeline.
Reporting Process
Please send reports to security@whalebone.io. A valid report should include:
Summary: A brief description of the vulnerability and its potential impact.
Reproduction steps: Clear, step-by-step instructions to reproduce the issue.
Proof of concept: Screenshots, screen recordings, or scripts showing the exploit.
Target details: The URL, endpoint, or software version affected.
What to Expect
When you report a vulnerability, we commit to:
Acknowledgment: We will acknowledge receipt of your report within three business days.
Triage: We will investigate and confirm the vulnerability as quickly as possible.
Remediation: We aim to fix critical issues within 10 days.


