Last updated/September 25, 2026
Vulnerability Disclosure Policy
Reporting a vulnerability
If you believe you've found a security vulnerability in westoakbridge.co or any system we operate, email security@westoakbridge.co. Our machine-readable contact details are published at /.well-known/security.txt.
What to include
- The affected URL or system and the type of issue
- Step-by-step instructions to reproduce it, with any proof-of-concept
- The impact you believe it has
- How you'd like to be credited, if at all
Scope
This policy covers westoakbridge.co and its subdomains. Systems belonging to our clients are out of scope: report those to the owner directly. Findings that only affect outdated browsers, missing best-practice headers with no demonstrated impact, and volumetric denial-of-service are out of scope.
Rules of engagement
- Only test against accounts and data you own
- Don't access, modify, or delete other people's data; stop and report as soon as you reach any
- No denial-of-service, spam, social engineering, or physical attacks
- Give us reasonable time to fix the issue before disclosing it publicly
What you can expect from us
We aim to acknowledge reports within three business days, keep you informed while we investigate, and tell you when the issue is fixed. With your permission, we'll credit you publicly. We don't currently run a paid bug bounty.
Safe harbor
If you act in good faith and follow this policy, we will not pursue or support legal action against you for your research, and we'll work with you to understand and resolve the issue quickly.