Aller au contenu principal

Vulnerability Disclosure Policy

Last updated: September 21, 2026

We welcome reports from security researchers and customers who believe they have found a vulnerability in OneWordCrew products, firmware, software or online services. Coordinated disclosure helps us protect users, and we will work with you in good faith.

How to report

Send your report through our contact page with the subject line "Security report", and include: the affected product, software or service and its version; the environment in which the issue was observed; clear steps to reproduce; the potential impact; and any proof-of-concept material needed to confirm the issue.

What to expect from us

We aim to acknowledge reports promptly, keep you informed as we investigate, and tell you whether the report is accepted and what remediation is planned. Fix timelines depend on severity and complexity; we may ask for clarification or for more detail on reproduction.

Please do not

While investigating, please do not: access, modify or delete data that does not belong to you; degrade or disrupt our services or those of other users; use social engineering, phishing or physical attacks against our staff or premises; or publicly disclose details of the issue before we have had a reasonable opportunity to release a fix.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will not pursue or support legal action against you for that research, and we will make this clear to any third party that asks. This assurance does not extend to activities that violate the law or the rights of others.

Out of scope

Reports that rely only on outdated browsers or operating systems, automated scanner output without demonstrated impact, missing security headers without a practical exploit, or social engineering of our staff are generally not eligible for acknowledgement.