Trust

Security Reporting

How to responsibly report a potential Wallops Watch vulnerability.

Effective: September 11, 2026

Report privately

Email hello@wallopswatch.com with a concise description, affected URL, reproduction steps, impact, and supporting evidence. Do not include real passwords, private user data, or unnecessary personal information.

Testing boundaries

Do not access another user’s data, disrupt availability, send spam, use social engineering, test NASA or another third party, persist after demonstrating the issue, or publicly disclose an unresolved vulnerability. Production penetration testing requires prior written authorization. Course exercises belong only in the isolated local training lab with synthetic data.

Good-faith response

We will make a good-faith effort to acknowledge credible reports, investigate them, and communicate remediation status. This page is not a promise of payment, a bug-bounty program, or authorization for testing outside the stated boundaries.