Security & Vulnerability Disclosure Policy

Last Updated: April 12, 2026

The security of our users' data and our infrastructure is a top priority. We welcome and appreciate responsible security research. This policy outlines how to report vulnerabilities and what to expect from us in return.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in WCAG Repair, please report it to us responsibly:

Email: security@wcagrepair.com

Please include the following in your report:

  • A description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • The URL(s) or component(s) affected
  • Any proof-of-concept code or screenshots
  • Your name and contact information (for follow-up)

What We Ask

  • Do not access, modify, or delete data belonging to other users
  • Do not perform denial-of-service attacks or load testing
  • Do not send unsolicited messages to users as part of your testing
  • Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it
  • Do make a good-faith effort to avoid privacy violations and disruption to the Service
  • Do limit your testing to your own accounts and test data

Our Commitment

  • We will acknowledge your report within 2 business days
  • We will provide an initial assessment within 5 business days
  • We will keep you informed of our progress toward resolving the issue
  • We will not pursue legal action against researchers who follow this policy in good faith
  • We will credit you (if desired) when we disclose the fix, unless you prefer to remain anonymous

Scope

The following are in scope for security research:

  • wcagrepair.com and all subdomains
  • Our web application, API endpoints, and authentication mechanisms
  • Data exposure, injection, access control, and authentication vulnerabilities

The following are out of scope:

  • Third-party services (Stripe, Cloudflare, Anthropic) — report these to the respective vendor
  • Social engineering or phishing attacks against our team
  • Physical attacks against our infrastructure
  • Denial-of-service vulnerabilities (we are aware of inherent rate-limit boundaries)
  • Issues in third-party libraries with no demonstrable impact on our Service
  • Missing security headers that have no exploitable impact
  • SPF/DKIM/DMARC configuration issues (report these separately to support@wcagrepair.com)

Infrastructure Security

For transparency, here is an overview of our security practices:

  • All traffic is proxied through Cloudflare with WAF rules and DDoS protection
  • Application servers are firewalled with nftables; only necessary ports are exposed
  • Database access is restricted to application servers only
  • TLS 1.2+ is enforced on all connections
  • Dependencies are regularly updated and monitored for known vulnerabilities
  • Automated bot detection and IP-based blocking for malicious activity

Machine-Readable Policy

Our security.txt file is available at the standard location for automated discovery:

https://wcagrepair.com/.well-known/security.txt