Security & Vulnerability Disclosure Policy
Last Updated: April 12, 2026
The security of our users' data and our infrastructure is a top priority. We welcome and appreciate responsible security research. This policy outlines how to report vulnerabilities and what to expect from us in return.
Reporting a Vulnerability
If you believe you have discovered a security vulnerability in WCAG Repair, please report it to us responsibly:
Email: security@wcagrepair.com
Please include the following in your report:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The URL(s) or component(s) affected
- Any proof-of-concept code or screenshots
- Your name and contact information (for follow-up)
What We Ask
- Do not access, modify, or delete data belonging to other users
- Do not perform denial-of-service attacks or load testing
- Do not send unsolicited messages to users as part of your testing
- Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it
- Do make a good-faith effort to avoid privacy violations and disruption to the Service
- Do limit your testing to your own accounts and test data
Our Commitment
- We will acknowledge your report within 2 business days
- We will provide an initial assessment within 5 business days
- We will keep you informed of our progress toward resolving the issue
- We will not pursue legal action against researchers who follow this policy in good faith
- We will credit you (if desired) when we disclose the fix, unless you prefer to remain anonymous
Scope
The following are in scope for security research:
- wcagrepair.com and all subdomains
- Our web application, API endpoints, and authentication mechanisms
- Data exposure, injection, access control, and authentication vulnerabilities
The following are out of scope:
- Third-party services (Stripe, Cloudflare, Anthropic) — report these to the respective vendor
- Social engineering or phishing attacks against our team
- Physical attacks against our infrastructure
- Denial-of-service vulnerabilities (we are aware of inherent rate-limit boundaries)
- Issues in third-party libraries with no demonstrable impact on our Service
- Missing security headers that have no exploitable impact
- SPF/DKIM/DMARC configuration issues (report these separately to support@wcagrepair.com)
Infrastructure Security
For transparency, here is an overview of our security practices:
- All traffic is proxied through Cloudflare with WAF rules and DDoS protection
- Application servers are firewalled with nftables; only necessary ports are exposed
- Database access is restricted to application servers only
- TLS 1.2+ is enforced on all connections
- Dependencies are regularly updated and monitored for known vulnerabilities
- Automated bot detection and IP-based blocking for malicious activity
Machine-Readable Policy
Our security.txt file is available at the standard location for automated discovery:
https://wcagrepair.com/.well-known/security.txt