Report a security issue
If you believe you have found a security vulnerability in Wiggle BOS, please email security@wigglebos.com. We read every report. Please include:
- What you found and where (the page, address or API endpoint)
- Steps to reproduce it, and what an attacker could do with it
- Any proof of concept, screenshots or requests, with other people's data removed
- How we can reach you, and whether you would like to be credited
What we commit to
- We will confirm we received your report within 3 business days.
- We will keep you updated while we investigate and fix it, and tell you when it is resolved.
- We will credit you on request once the issue is fixed. We do not currently offer paid rewards.
Scope
In scope: app.wigglebos.com, wigglebos.com, demo.wigglebos.com, the Wiggle BOS API and its sign-in, the pages, proposals, forms and websites Wiggle hosts, and the Wiggle desktop, phone and Outlook apps.
Out of scope: denial of service or load testing; spam or social engineering of our staff or customers; physical attacks; issues in services we connect to, which should go to their owners; and reports from automated scanners, or about missing headers or best practices, without a demonstrated security impact.
Rules for good-faith research
- Use only accounts and workspaces you own or have permission to test. Never access, change or delete other people's data beyond the minimum needed to show the issue, and stop and tell us as soon as you see any.
- Do not degrade the service for others, and do not run bulk automated scans.
- Give us reasonable time to fix the issue before telling anyone else, normally 90 days, and agree the timing with us.
Safe harbor
If you follow this policy in good faith, we will consider your research authorized, we will not pursue legal action against you for it, and section 9 of our Terms of Service (automated access and scraping) will not be used against you for that research. If a third party takes legal action against you for research done under this policy, we will make it known that your activity was authorized by us.
More
How we protect data is described on our Trust page. Our machine-readable contact file is at /.well-known/security.txt.