Effective: September 11, 2026
Report privately
Email hello@wallopswatch.com with a concise description, affected URL, reproduction steps, impact, and supporting evidence. Do not include real passwords, private user data, or unnecessary personal information.
Testing boundaries
Do not access another user’s data, disrupt availability, send spam, use social engineering, test NASA or another third party, persist after demonstrating the issue, or publicly disclose an unresolved vulnerability. Production penetration testing requires prior written authorization. Course exercises belong only in the isolated local training lab with synthetic data.
Good-faith response
We will make a good-faith effort to acknowledge credible reports, investigate them, and communicate remediation status. This page is not a promise of payment, a bug-bounty program, or authorization for testing outside the stated boundaries.
