Responsible Disclosure

We treat security reports as a partnership. If you've found a vulnerability in the WAB protocol, SDK, server, or hosted infrastructure, please report it privately and we will respond, fix, and credit.

1. How to report

Emailsecurity@webagentbridge.com
PGP fingerprintto be published
Acknowledge SLA≤ 72 hours
Triage SLA≤ 7 days
Fix SLA (critical)≤ 14 days from triage
Please encrypt reports of critical issues with our PGP key. If PGP is impractical, send an unencrypted summary plus a request for a secure channel, and we will set one up within 24 hours.

2. Scope

In scope:

Out of scope:

3. Safe harbor

Researchers acting in good faith under this policy are authorized to perform their work and will not be pursued under the CFAA, equivalents elsewhere, or our own terms of service, provided they:

We will not pursue legal action against good-faith research that follows this policy.

4. Acknowledgement & rewards

SeverityExamplesReward
CriticalForged ATP receipts, full key extraction, complete account takeover, RCE on productionUSD 1,000 – 5,000 + hall of fame
HighReplay bypass, idempotency bypass, scope escalation, signed-intent forgery, persistent auth bypassUSD 250 – 1,000 + hall of fame
MediumAuthenticated IDOR, partial scope leak, server-side input flaws without RCEUSD 75 – 250 + hall of fame
LowReflected info disclosure, missing rate limits with no clear abuse pathHall of fame + swag

Rewards are paid at our discretion after the issue is verified, deduplicated, and fixed. First reporter of a unique issue is rewarded.

5. Process

  1. Report — email security@webagentbridge.com with reproduction steps, affected version, and impact.
  2. Acknowledge — we reply within 72 hours.
  3. Triage — within 7 days we confirm severity and assign a tracking ID.
  4. Remediate — fix and deploy. Critical within 14 days, others within 90 days.
  5. Disclose — coordinated public advisory after the fix ships, crediting the reporter unless they prefer anonymity.

6. Hall of fame

Reporters who follow this policy are listed here (with permission). The list will appear after our first credited disclosure.

7. Document history

Related: /security · /threat-model · /key-rotation